{
  "generated_at": "2026-08-26T11:57:02Z",
  "bounded_to": 500,
  "filters": {
    "q": "",
    "vendor": "",
    "urgency": "",
    "cycle": "",
    "product": "",
    "platform": "",
    "excludeGroups": [],
    "visibleVendors": [],
    "vendorSelectionActive": false,
    "exploitation": "",
    "restart": "",
    "knownIssue": "",
    "releaseDate": "",
    "cycleState": ""
  },
  "count": 500,
  "records": [
    {
      "id": "microsoft-2026-07-apps-msrc-2026-07-apps-release-notes-microsoft-pc-manager",
      "slug": "microsoft-2026-07-apps-msrc-2026-07-apps-release-notes-microsoft-pc-manager",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-07-apps-release-notes",
      "title": "Deploy Microsoft Apps update for Microsoft PC Manager",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://apps.microsoft.com/detail/9pm860492szd?hl=en-us&gl=US",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft PC Manager",
      "platform": "Apps",
      "release_version": "3.21.6.0, 3.22.1.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Microsoft PC Manager.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 2,
        "ids": [
          "CVE-2026-50438",
          "CVE-2026-58636"
        ],
        "details": [
          {
            "id": "CVE-2026-50438",
            "title": "Microsoft PC Manager Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0037,
            "epssPercentile": 0.30149,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58636",
            "title": "Microsoft PC Manager Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0037,
            "epssPercentile": 0.30149,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-50438",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-apps-msrc-2026-07-apps-release-notes-windows-terminal-for-windows-10",
      "slug": "microsoft-2026-07-apps-msrc-2026-07-apps-release-notes-windows-terminal-for-windows-10",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-07-apps-release-notes",
      "title": "Deploy Microsoft Apps update for Windows Terminal for Windows 10",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://apps.microsoft.com/store/detail/windows-terminal/9N0DX20HK701?hl=en-us&gl=us",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Windows Terminal for Windows 10",
      "platform": "Apps",
      "release_version": "1.24.11321.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows Terminal for Windows 10.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-54124"
        ],
        "details": [
          {
            "id": "CVE-2026-54124",
            "title": "Windows Terminal Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.388,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-54124",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-apps-msrc-2026-07-apps-release-notes-windows-terminal-for-windows-11",
      "slug": "microsoft-2026-07-apps-msrc-2026-07-apps-release-notes-windows-terminal-for-windows-11",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-07-apps-release-notes",
      "title": "Deploy Microsoft Apps update for Windows Terminal for Windows 11",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://apps.microsoft.com/store/detail/windows-terminal/9N0DX20HK701?hl=en-us&gl=us",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Windows Terminal for Windows 11",
      "platform": "Apps",
      "release_version": "1.24.11321.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows Terminal for Windows 11.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-54124"
        ],
        "details": [
          {
            "id": "CVE-2026-54124",
            "title": "Windows Terminal Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.388,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-54124",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-apps-msrc-2026-07-apps-release-notes-microsoft-bing-search-for-ios",
      "slug": "microsoft-2026-07-apps-msrc-2026-07-apps-release-notes-microsoft-bing-search-for-ios",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-07-apps-release-notes",
      "title": "Deploy Microsoft Apps update for Microsoft Bing Search for iOS",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://apps.apple.com/us/app/microsoft-bing-search/id345323231",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft Bing Search for iOS",
      "platform": "Apps",
      "release_version": "33.4.440529002",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Bing Search for iOS.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-58595"
        ],
        "details": [
          {
            "id": "CVE-2026-58595",
            "title": "Microsoft Bing App for IOS Spoofing Vulnerability",
            "summary": "Improper restriction of rendered ui layers or frames in Microsoft Bing App for IOS allows an unauthorized attacker to perform spoofing over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0069,
            "epssPercentile": 0.50492,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-58595",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-apps-msrc-2026-07-apps-release-notes-microsoft-365-copilot-for-ios",
      "slug": "microsoft-2026-07-apps-msrc-2026-07-apps-release-notes-microsoft-365-copilot-for-ios",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-07-apps-release-notes",
      "title": "Deploy Microsoft Apps update for Microsoft 365 Copilot for iOS",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://apps.apple.com/us/app/microsoft-365-copilot/id541164041",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft 365 Copilot for iOS",
      "platform": "Apps",
      "release_version": "2.111.4",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft 365 Copilot for iOS.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-58617"
        ],
        "details": [
          {
            "id": "CVE-2026-58617",
            "title": "M365 Copilot for iOS Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00787,
            "epssPercentile": 0.53823,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-58617",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-azure-msrc-2026-07-azure-release-notes-azure-connected-machine-agent",
      "slug": "microsoft-2026-07-azure-msrc-2026-07-azure-release-notes-azure-connected-machine-agent",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-07-azure-release-notes",
      "title": "Deploy Microsoft Azure update for Azure Connected Machine Agent",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://gbl.his.arc.azure.com/azcmagent/1.65/AzureConnectedMachineAgent.msi",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Azure Connected Machine Agent",
      "platform": "Azure",
      "release_version": "1.65",
      "action_type": "deploy-patch",
      "restart_required": "no",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Connected Machine Agent.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-47632"
        ],
        "details": [
          {
            "id": "CVE-2026-47632",
            "title": "Azure Connected Machine Agent Elevation of Privilege Vulnerability",
            "summary": "Improper certificate validation in Azure Connected Machine Agent allows an unauthorized attacker to elevate privileges over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00495,
            "epssPercentile": 0.40705,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-47632",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "The reviewed source does not require a restart.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-azure-msrc-2026-07-azure-release-notes-azure-spring-apps",
      "slug": "microsoft-2026-07-azure-msrc-2026-07-azure-release-notes-azure-spring-apps",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-07-azure-release-notes",
      "title": "Deploy Microsoft Azure update for Azure Spring Apps",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://repo1.maven.org/maven2/com/azure/spring/spring-cloud-azure-starter-active-directory-b2c/7.3.0/",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Azure Spring Apps",
      "platform": "Azure",
      "release_version": "7.3.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Spring Apps.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-50338"
        ],
        "details": [
          {
            "id": "CVE-2026-50338",
            "title": "Azure Spring Apps Elevation of Privilege Vulnerability",
            "summary": "Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges over a network.",
            "score": 8.2,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00517,
            "epssPercentile": 0.42122,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.2,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-50338",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-azure-msrc-2026-07-azure-release-notes-azure-active-directory",
      "slug": "microsoft-2026-07-azure-msrc-2026-07-azure-release-notes-azure-active-directory",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-07-azure-release-notes",
      "title": "Deploy Microsoft Azure update for Azure Active Directory",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/releases/tag/5.7.1",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Azure Active Directory",
      "platform": "Azure",
      "release_version": "5.7.1, 7.7.3, 8.19.2",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Azure Active Directory.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 2,
        "ids": [
          "CVE-2026-50652",
          "CVE-2026-50653"
        ],
        "details": [
          {
            "id": "CVE-2026-50652",
            "title": "Azure Active Directory Denial of Service Vulnerability",
            "summary": "Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0173,
            "epssPercentile": 0.76079,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50653",
            "title": "Azure Active Directory Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.5,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-50653",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-azure-msrc-2026-07-azure-release-notes-azure-cyclecloud-8-9-1",
      "slug": "microsoft-2026-07-azure-msrc-2026-07-azure-release-notes-azure-cyclecloud-8-9-1",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-07-azure-release-notes",
      "title": "Deploy Microsoft Azure update for Azure CycleCloud 8.9.1",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://marketplace.microsoft.com/en-us/product/azurecyclecloud.azure-cyclecloud?tab=Overview",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Azure CycleCloud 8.9.1",
      "platform": "Azure",
      "release_version": "8.9.1",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Azure CycleCloud 8.9.1.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 2,
        "ids": [
          "CVE-2026-57969",
          "CVE-2026-58279"
        ],
        "details": [
          {
            "id": "CVE-2026-57969",
            "title": "Azure CycleCloud Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00527,
            "epssPercentile": 0.42735,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58279",
            "title": "Azure CycleCloud Elevation of Privilege Vulnerability",
            "summary": "Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00644,
            "epssPercentile": 0.48593,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-57969",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-browser-msrc-2026-07-browser-release-notes-microsoft-edge-copilot-for-android",
      "slug": "microsoft-2026-07-browser-msrc-2026-07-browser-release-notes-microsoft-edge-copilot-for-android",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-07-browser-release-notes",
      "title": "Deploy Microsoft Browser update for Microsoft Edge Copilot for Android",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://play.google.com/store/apps/details?id=com.microsoft.emmx&hl=en_US&pli=1",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft Edge Copilot for Android",
      "platform": "Browser",
      "release_version": null,
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Edge Copilot for Android.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-48561"
        ],
        "details": [
          {
            "id": "CVE-2026-48561",
            "title": "Microsoft Edge Copilot Remote Code Execution Vulnerability",
            "summary": "Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network.",
            "score": 9.6,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00863,
            "epssPercentile": 0.56246,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.6,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-48561",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-browser-msrc-2026-07-browser-release-notes-microsoft-edge-copilot-for-ios",
      "slug": "microsoft-2026-07-browser-msrc-2026-07-browser-release-notes-microsoft-edge-copilot-for-ios",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-07-browser-release-notes",
      "title": "Deploy Microsoft Browser update for Microsoft Edge Copilot for IOS",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://apps.apple.com/us/app/microsoft-edge/id1288723196",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft Edge Copilot for IOS",
      "platform": "Browser",
      "release_version": null,
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Edge Copilot for IOS.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-48561"
        ],
        "details": [
          {
            "id": "CVE-2026-48561",
            "title": "Microsoft Edge Copilot Remote Code Execution Vulnerability",
            "summary": "Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network.",
            "score": 9.6,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00863,
            "epssPercentile": 0.56246,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.6,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-48561",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-developer-tools-kb5099535",
      "slug": "microsoft-2026-07-developer-tools-kb5099535",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5099535",
      "title": "Deploy Microsoft Developer Tools security update KB5099535",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5099535",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2016, plus 1 more",
      "platform": "Developer Tools",
      "release_version": "2.0.50727.8983 & 3.0.30729.8978 & 4.7.4143.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 17 linked CVEs for Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2016, plus 1 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 17,
        "ids": [
          "CVE-2026-47302",
          "CVE-2026-47304",
          "CVE-2026-50304",
          "CVE-2026-50324",
          "CVE-2026-50355",
          "CVE-2026-50368",
          "CVE-2026-50411",
          "CVE-2026-50525",
          "CVE-2026-50527",
          "CVE-2026-50646",
          "CVE-2026-50647",
          "CVE-2026-50648",
          "CVE-2026-50649",
          "CVE-2026-50650",
          "CVE-2026-50652",
          "CVE-2026-50653",
          "CVE-2026-50659"
        ],
        "details": [
          {
            "id": "CVE-2026-47302",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01029,
            "epssPercentile": 0.61433,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47304",
            "title": ".NET Security Feature Bypass Vulnerability",
            "summary": "Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00216,
            "epssPercentile": 0.1193,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50304",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50324",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00855,
            "epssPercentile": 0.5598,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50355",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50368",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50411",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50525",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00604,
            "epssPercentile": 0.46716,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50527",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50646",
            "title": ".NET Framework Remote Code Execution Vulnerability",
            "summary": "Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00969,
            "epssPercentile": 0.59587,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50647",
            "title": "Active Directory Federation Server Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50648",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50649",
            "title": ".NET Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00938,
            "epssPercentile": 0.58565,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50650",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00296,
            "epssPercentile": 0.21888,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50652",
            "title": "Azure Active Directory Denial of Service Vulnerability",
            "summary": "Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0173,
            "epssPercentile": 0.76079,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50653",
            "title": "Azure Active Directory Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50659",
            "title": ".NET Spoofing Vulnerability",
            "summary": "Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0055,
            "epssPercentile": 0.44029,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-47304",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-developer-tools-kb5100984",
      "slug": "microsoft-2026-07-developer-tools-kb5100984",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5100984",
      "title": "Deploy Microsoft Developer Tools security update KB5100984",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5100984",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft .NET Framework 3.5 on Windows Server 2012, Microsoft .NET Framework 3.5 on Windows Server 2012 (Server Core installation)",
      "platform": "Developer Tools",
      "release_version": "2.0.50727.8983 & 3.0.30729.8978",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 11 linked CVEs for Microsoft .NET Framework 3.5 on Windows Server 2012, Microsoft .NET Framework 3.5 on Windows Server 2012 (Server Core installation).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 11,
        "ids": [
          "CVE-2026-47302",
          "CVE-2026-47304",
          "CVE-2026-50525",
          "CVE-2026-50527",
          "CVE-2026-50646",
          "CVE-2026-50648",
          "CVE-2026-50649",
          "CVE-2026-50650",
          "CVE-2026-50652",
          "CVE-2026-50653",
          "CVE-2026-50659"
        ],
        "details": [
          {
            "id": "CVE-2026-47302",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01029,
            "epssPercentile": 0.61433,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47304",
            "title": ".NET Security Feature Bypass Vulnerability",
            "summary": "Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00216,
            "epssPercentile": 0.1193,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50525",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00604,
            "epssPercentile": 0.46716,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50527",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50646",
            "title": ".NET Framework Remote Code Execution Vulnerability",
            "summary": "Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00969,
            "epssPercentile": 0.59587,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50648",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50649",
            "title": ".NET Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00938,
            "epssPercentile": 0.58565,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50650",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00296,
            "epssPercentile": 0.21888,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50652",
            "title": "Azure Active Directory Denial of Service Vulnerability",
            "summary": "Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0173,
            "epssPercentile": 0.76079,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50653",
            "title": "Azure Active Directory Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50659",
            "title": ".NET Spoofing Vulnerability",
            "summary": "Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0055,
            "epssPercentile": 0.44029,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-47304",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-developer-tools-kb5100985",
      "slug": "microsoft-2026-07-developer-tools-kb5100985",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5100985",
      "title": "Deploy Microsoft Developer Tools security update KB5100985",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5100985",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft .NET Framework 3.5 on Windows Server 2012 R2, Microsoft .NET Framework 3.5 on Windows Server 2012 R2 (Server Core installation)",
      "platform": "Developer Tools",
      "release_version": "2.0.50727.8983 & 3.0.30729.8978",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 11 linked CVEs for Microsoft .NET Framework 3.5 on Windows Server 2012 R2, Microsoft .NET Framework 3.5 on Windows Server 2012 R2 (Server Core installation).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 11,
        "ids": [
          "CVE-2026-47302",
          "CVE-2026-47304",
          "CVE-2026-50525",
          "CVE-2026-50527",
          "CVE-2026-50646",
          "CVE-2026-50648",
          "CVE-2026-50649",
          "CVE-2026-50650",
          "CVE-2026-50652",
          "CVE-2026-50653",
          "CVE-2026-50659"
        ],
        "details": [
          {
            "id": "CVE-2026-47302",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01029,
            "epssPercentile": 0.61433,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47304",
            "title": ".NET Security Feature Bypass Vulnerability",
            "summary": "Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00216,
            "epssPercentile": 0.1193,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50525",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00604,
            "epssPercentile": 0.46716,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50527",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50646",
            "title": ".NET Framework Remote Code Execution Vulnerability",
            "summary": "Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00969,
            "epssPercentile": 0.59587,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50648",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50649",
            "title": ".NET Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00938,
            "epssPercentile": 0.58565,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50650",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00296,
            "epssPercentile": 0.21888,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50652",
            "title": "Azure Active Directory Denial of Service Vulnerability",
            "summary": "Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0173,
            "epssPercentile": 0.76079,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50653",
            "title": "Azure Active Directory Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50659",
            "title": ".NET Spoofing Vulnerability",
            "summary": "Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0055,
            "epssPercentile": 0.44029,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-47304",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-developer-tools-kb5100989",
      "slug": "microsoft-2026-07-developer-tools-kb5100989",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5100989",
      "title": "Deploy Microsoft Developer Tools security update KB5100989",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5100989",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for x64-based Systems, plus 2 more",
      "platform": "Developer Tools",
      "release_version": "2.0.50727.9069 & 3.0.30729.9067 & 4.7.4143.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 17 linked CVEs for Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for x64-based Systems, plus 2 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 17,
        "ids": [
          "CVE-2026-47302",
          "CVE-2026-47304",
          "CVE-2026-50304",
          "CVE-2026-50324",
          "CVE-2026-50355",
          "CVE-2026-50368",
          "CVE-2026-50411",
          "CVE-2026-50525",
          "CVE-2026-50527",
          "CVE-2026-50646",
          "CVE-2026-50647",
          "CVE-2026-50648",
          "CVE-2026-50649",
          "CVE-2026-50650",
          "CVE-2026-50652",
          "CVE-2026-50653",
          "CVE-2026-50659"
        ],
        "details": [
          {
            "id": "CVE-2026-47302",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01029,
            "epssPercentile": 0.61433,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47304",
            "title": ".NET Security Feature Bypass Vulnerability",
            "summary": "Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00216,
            "epssPercentile": 0.1193,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50304",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50324",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00855,
            "epssPercentile": 0.5598,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50355",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50368",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50411",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50525",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00604,
            "epssPercentile": 0.46716,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50527",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50646",
            "title": ".NET Framework Remote Code Execution Vulnerability",
            "summary": "Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00969,
            "epssPercentile": 0.59587,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50647",
            "title": "Active Directory Federation Server Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50648",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50649",
            "title": ".NET Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00938,
            "epssPercentile": 0.58565,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50650",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00296,
            "epssPercentile": 0.21888,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50652",
            "title": "Azure Active Directory Denial of Service Vulnerability",
            "summary": "Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0173,
            "epssPercentile": 0.76079,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50653",
            "title": "Azure Active Directory Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50659",
            "title": ".NET Spoofing Vulnerability",
            "summary": "Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0055,
            "epssPercentile": 0.44029,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-47304",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-developer-tools-kb5100990",
      "slug": "microsoft-2026-07-developer-tools-kb5100990",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5100990",
      "title": "Deploy Microsoft Developer Tools security update KB5100990",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5100990",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 (Server Core installation)",
      "platform": "Developer Tools",
      "release_version": "4.7.4143.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 17 linked CVEs for Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 (Server Core installation).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 17,
        "ids": [
          "CVE-2026-47302",
          "CVE-2026-47304",
          "CVE-2026-50304",
          "CVE-2026-50324",
          "CVE-2026-50355",
          "CVE-2026-50368",
          "CVE-2026-50411",
          "CVE-2026-50525",
          "CVE-2026-50527",
          "CVE-2026-50646",
          "CVE-2026-50647",
          "CVE-2026-50648",
          "CVE-2026-50649",
          "CVE-2026-50650",
          "CVE-2026-50652",
          "CVE-2026-50653",
          "CVE-2026-50659"
        ],
        "details": [
          {
            "id": "CVE-2026-47302",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01029,
            "epssPercentile": 0.61433,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47304",
            "title": ".NET Security Feature Bypass Vulnerability",
            "summary": "Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00216,
            "epssPercentile": 0.1193,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50304",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50324",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00855,
            "epssPercentile": 0.5598,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50355",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50368",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50411",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50525",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00604,
            "epssPercentile": 0.46716,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50527",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50646",
            "title": ".NET Framework Remote Code Execution Vulnerability",
            "summary": "Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00969,
            "epssPercentile": 0.59587,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50647",
            "title": "Active Directory Federation Server Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50648",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50649",
            "title": ".NET Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00938,
            "epssPercentile": 0.58565,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50650",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00296,
            "epssPercentile": 0.21888,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50652",
            "title": "Azure Active Directory Denial of Service Vulnerability",
            "summary": "Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0173,
            "epssPercentile": 0.76079,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50653",
            "title": "Azure Active Directory Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50659",
            "title": ".NET Spoofing Vulnerability",
            "summary": "Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0055,
            "epssPercentile": 0.44029,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-47304",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-developer-tools-kb5100991",
      "slug": "microsoft-2026-07-developer-tools-kb5100991",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5100991",
      "title": "Deploy Microsoft Developer Tools security update KB5100991",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5100991",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2 (Server Core installation)",
      "platform": "Developer Tools",
      "release_version": "4.7.4143.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 17 linked CVEs for Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2 (Server Core installation).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 17,
        "ids": [
          "CVE-2026-47302",
          "CVE-2026-47304",
          "CVE-2026-50304",
          "CVE-2026-50324",
          "CVE-2026-50355",
          "CVE-2026-50368",
          "CVE-2026-50411",
          "CVE-2026-50525",
          "CVE-2026-50527",
          "CVE-2026-50646",
          "CVE-2026-50647",
          "CVE-2026-50648",
          "CVE-2026-50649",
          "CVE-2026-50650",
          "CVE-2026-50652",
          "CVE-2026-50653",
          "CVE-2026-50659"
        ],
        "details": [
          {
            "id": "CVE-2026-47302",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01029,
            "epssPercentile": 0.61433,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47304",
            "title": ".NET Security Feature Bypass Vulnerability",
            "summary": "Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00216,
            "epssPercentile": 0.1193,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50304",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50324",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00855,
            "epssPercentile": 0.5598,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50355",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50368",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50411",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50525",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00604,
            "epssPercentile": 0.46716,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50527",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50646",
            "title": ".NET Framework Remote Code Execution Vulnerability",
            "summary": "Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00969,
            "epssPercentile": 0.59587,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50647",
            "title": "Active Directory Federation Server Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50648",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50649",
            "title": ".NET Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00938,
            "epssPercentile": 0.58565,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50650",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00296,
            "epssPercentile": 0.21888,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50652",
            "title": "Azure Active Directory Denial of Service Vulnerability",
            "summary": "Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0173,
            "epssPercentile": 0.76079,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50653",
            "title": "Azure Active Directory Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50659",
            "title": ".NET Spoofing Vulnerability",
            "summary": "Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0055,
            "epssPercentile": 0.44029,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-47304",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-developer-tools-kb5100998",
      "slug": "microsoft-2026-07-developer-tools-kb5100998",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5100998",
      "title": "Deploy Microsoft Developer Tools security update KB5100998",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5100998",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 25H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 25H2 for x64-based Systems",
      "platform": "Developer Tools",
      "release_version": "2.0.50727.9182 & 3.0.30729.9168 & 4.8.9340.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 17 linked CVEs for Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 25H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 25H2 for x64-based Systems.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 17,
        "ids": [
          "CVE-2026-47302",
          "CVE-2026-47304",
          "CVE-2026-50304",
          "CVE-2026-50324",
          "CVE-2026-50355",
          "CVE-2026-50368",
          "CVE-2026-50411",
          "CVE-2026-50525",
          "CVE-2026-50527",
          "CVE-2026-50646",
          "CVE-2026-50647",
          "CVE-2026-50648",
          "CVE-2026-50649",
          "CVE-2026-50650",
          "CVE-2026-50652",
          "CVE-2026-50653",
          "CVE-2026-50659"
        ],
        "details": [
          {
            "id": "CVE-2026-47302",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01029,
            "epssPercentile": 0.61433,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47304",
            "title": ".NET Security Feature Bypass Vulnerability",
            "summary": "Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00216,
            "epssPercentile": 0.1193,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50304",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50324",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00855,
            "epssPercentile": 0.5598,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50355",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50368",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50411",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50525",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00604,
            "epssPercentile": 0.46716,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50527",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50646",
            "title": ".NET Framework Remote Code Execution Vulnerability",
            "summary": "Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00969,
            "epssPercentile": 0.59587,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50647",
            "title": "Active Directory Federation Server Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50648",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50649",
            "title": ".NET Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00938,
            "epssPercentile": 0.58565,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50650",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00296,
            "epssPercentile": 0.21888,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50652",
            "title": "Azure Active Directory Denial of Service Vulnerability",
            "summary": "Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0173,
            "epssPercentile": 0.76079,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50653",
            "title": "Azure Active Directory Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50659",
            "title": ".NET Spoofing Vulnerability",
            "summary": "Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0055,
            "epssPercentile": 0.44029,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-47304",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-developer-tools-kb5101000",
      "slug": "microsoft-2026-07-developer-tools-kb5101000",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5101000",
      "title": "Deploy Microsoft Developer Tools security update KB5101000",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5101000",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for x64-based Systems, plus 3 more",
      "platform": "Developer Tools",
      "release_version": "2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 17 linked CVEs for Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for x64-based Systems, plus 3 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 17,
        "ids": [
          "CVE-2026-47302",
          "CVE-2026-47304",
          "CVE-2026-50304",
          "CVE-2026-50324",
          "CVE-2026-50355",
          "CVE-2026-50368",
          "CVE-2026-50411",
          "CVE-2026-50525",
          "CVE-2026-50527",
          "CVE-2026-50646",
          "CVE-2026-50647",
          "CVE-2026-50648",
          "CVE-2026-50649",
          "CVE-2026-50650",
          "CVE-2026-50652",
          "CVE-2026-50653",
          "CVE-2026-50659"
        ],
        "details": [
          {
            "id": "CVE-2026-47302",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01029,
            "epssPercentile": 0.61433,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47304",
            "title": ".NET Security Feature Bypass Vulnerability",
            "summary": "Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00216,
            "epssPercentile": 0.1193,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50304",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50324",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00855,
            "epssPercentile": 0.5598,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50355",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50368",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50411",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50525",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00604,
            "epssPercentile": 0.46716,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50527",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50646",
            "title": ".NET Framework Remote Code Execution Vulnerability",
            "summary": "Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00969,
            "epssPercentile": 0.59587,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50647",
            "title": "Active Directory Federation Server Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50648",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50649",
            "title": ".NET Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00938,
            "epssPercentile": 0.58565,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50650",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00296,
            "epssPercentile": 0.21888,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50652",
            "title": "Azure Active Directory Denial of Service Vulnerability",
            "summary": "Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0173,
            "epssPercentile": 0.76079,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50653",
            "title": "Azure Active Directory Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50659",
            "title": ".NET Spoofing Vulnerability",
            "summary": "Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0055,
            "epssPercentile": 0.44029,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-47304",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-developer-tools-kb5101001",
      "slug": "microsoft-2026-07-developer-tools-kb5101001",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5101001",
      "title": "Deploy Microsoft Developer Tools security update KB5101001",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5101001",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 24H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 24H2 for x64-based Systems",
      "platform": "Developer Tools",
      "release_version": "2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 17 linked CVEs for Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 24H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 24H2 for x64-based Systems.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 17,
        "ids": [
          "CVE-2026-47302",
          "CVE-2026-47304",
          "CVE-2026-50304",
          "CVE-2026-50324",
          "CVE-2026-50355",
          "CVE-2026-50368",
          "CVE-2026-50411",
          "CVE-2026-50525",
          "CVE-2026-50527",
          "CVE-2026-50646",
          "CVE-2026-50647",
          "CVE-2026-50648",
          "CVE-2026-50649",
          "CVE-2026-50650",
          "CVE-2026-50652",
          "CVE-2026-50653",
          "CVE-2026-50659"
        ],
        "details": [
          {
            "id": "CVE-2026-47302",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01029,
            "epssPercentile": 0.61433,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47304",
            "title": ".NET Security Feature Bypass Vulnerability",
            "summary": "Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00216,
            "epssPercentile": 0.1193,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50304",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50324",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00855,
            "epssPercentile": 0.5598,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50355",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50368",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50411",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50525",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00604,
            "epssPercentile": 0.46716,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50527",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50646",
            "title": ".NET Framework Remote Code Execution Vulnerability",
            "summary": "Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00969,
            "epssPercentile": 0.59587,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50647",
            "title": "Active Directory Federation Server Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50648",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50649",
            "title": ".NET Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00938,
            "epssPercentile": 0.58565,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50650",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00296,
            "epssPercentile": 0.21888,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50652",
            "title": "Azure Active Directory Denial of Service Vulnerability",
            "summary": "Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0173,
            "epssPercentile": 0.76079,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50653",
            "title": "Azure Active Directory Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50659",
            "title": ".NET Spoofing Vulnerability",
            "summary": "Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0055,
            "epssPercentile": 0.44029,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-47304",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-developer-tools-kb5101002",
      "slug": "microsoft-2026-07-developer-tools-kb5101002",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5101002",
      "title": "Deploy Microsoft Developer Tools security update KB5101002",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5101002",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 26H1 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 version 26H1 for x64-based Systems, Microsoft .NET Framework 4.8.1 on Windows 11 Version 26H1 for ARM64-based Systems, plus 1 more",
      "platform": "Developer Tools",
      "release_version": "4.8.9340.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 17 linked CVEs for Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 26H1 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 version 26H1 for x64-based Systems, Microsoft .NET Framework 4.8.1 on Windows 11 Version 26H1 for ARM64-based Systems, plus 1 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 17,
        "ids": [
          "CVE-2026-47302",
          "CVE-2026-47304",
          "CVE-2026-50304",
          "CVE-2026-50324",
          "CVE-2026-50355",
          "CVE-2026-50368",
          "CVE-2026-50411",
          "CVE-2026-50525",
          "CVE-2026-50527",
          "CVE-2026-50646",
          "CVE-2026-50647",
          "CVE-2026-50648",
          "CVE-2026-50649",
          "CVE-2026-50650",
          "CVE-2026-50652",
          "CVE-2026-50653",
          "CVE-2026-50659"
        ],
        "details": [
          {
            "id": "CVE-2026-47302",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01029,
            "epssPercentile": 0.61433,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47304",
            "title": ".NET Security Feature Bypass Vulnerability",
            "summary": "Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00216,
            "epssPercentile": 0.1193,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50304",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50324",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00855,
            "epssPercentile": 0.5598,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50355",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50368",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50411",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50525",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00604,
            "epssPercentile": 0.46716,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50527",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50646",
            "title": ".NET Framework Remote Code Execution Vulnerability",
            "summary": "Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00969,
            "epssPercentile": 0.59587,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50647",
            "title": "Active Directory Federation Server Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50648",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50649",
            "title": ".NET Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00938,
            "epssPercentile": 0.58565,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50650",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00296,
            "epssPercentile": 0.21888,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50652",
            "title": "Azure Active Directory Denial of Service Vulnerability",
            "summary": "Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0173,
            "epssPercentile": 0.76079,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50653",
            "title": "Azure Active Directory Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50659",
            "title": ".NET Spoofing Vulnerability",
            "summary": "Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0055,
            "epssPercentile": 0.44029,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-47304",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-developer-tools-kb5101003",
      "slug": "microsoft-2026-07-developer-tools-kb5101003",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5101003",
      "title": "Deploy Microsoft Developer Tools security update KB5101003",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5101003",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2025, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2025 (Server Core installation)",
      "platform": "Developer Tools",
      "release_version": "2.0.50727.9182 & 3.0.30729.9168 & 4.8.9340.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2025, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2025 (Server Core installation).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-47304"
        ],
        "details": [
          {
            "id": "CVE-2026-47304",
            "title": ".NET Security Feature Bypass Vulnerability",
            "summary": "Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00216,
            "epssPercentile": 0.1193,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-47304",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-developer-tools-kb5101004",
      "slug": "microsoft-2026-07-developer-tools-kb5101004",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5101004",
      "title": "Deploy Microsoft Developer Tools security update KB5101004",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5101004",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 23H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 23H2 for x64-based Systems",
      "platform": "Developer Tools",
      "release_version": "2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 17 linked CVEs for Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 23H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 23H2 for x64-based Systems.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 17,
        "ids": [
          "CVE-2026-47302",
          "CVE-2026-47304",
          "CVE-2026-50304",
          "CVE-2026-50324",
          "CVE-2026-50355",
          "CVE-2026-50368",
          "CVE-2026-50411",
          "CVE-2026-50525",
          "CVE-2026-50527",
          "CVE-2026-50646",
          "CVE-2026-50647",
          "CVE-2026-50648",
          "CVE-2026-50649",
          "CVE-2026-50650",
          "CVE-2026-50652",
          "CVE-2026-50653",
          "CVE-2026-50659"
        ],
        "details": [
          {
            "id": "CVE-2026-47302",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01029,
            "epssPercentile": 0.61433,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47304",
            "title": ".NET Security Feature Bypass Vulnerability",
            "summary": "Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00216,
            "epssPercentile": 0.1193,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50304",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50324",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00855,
            "epssPercentile": 0.5598,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50355",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50368",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50411",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50525",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00604,
            "epssPercentile": 0.46716,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50527",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50646",
            "title": ".NET Framework Remote Code Execution Vulnerability",
            "summary": "Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00969,
            "epssPercentile": 0.59587,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50647",
            "title": "Active Directory Federation Server Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50648",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50649",
            "title": ".NET Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00938,
            "epssPercentile": 0.58565,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50650",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00296,
            "epssPercentile": 0.21888,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50652",
            "title": "Azure Active Directory Denial of Service Vulnerability",
            "summary": "Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0173,
            "epssPercentile": 0.76079,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50653",
            "title": "Azure Active Directory Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50659",
            "title": ".NET Spoofing Vulnerability",
            "summary": "Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0055,
            "epssPercentile": 0.44029,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-47304",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-developer-tools-kb5101005",
      "slug": "microsoft-2026-07-developer-tools-kb5101005",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5101005",
      "title": "Deploy Microsoft Developer Tools security update KB5101005",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5101005",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2022, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2022 (Server Core installation)",
      "platform": "Developer Tools",
      "release_version": "2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 17 linked CVEs for Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2022, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2022 (Server Core installation).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 17,
        "ids": [
          "CVE-2026-47302",
          "CVE-2026-47304",
          "CVE-2026-50304",
          "CVE-2026-50324",
          "CVE-2026-50355",
          "CVE-2026-50368",
          "CVE-2026-50411",
          "CVE-2026-50525",
          "CVE-2026-50527",
          "CVE-2026-50646",
          "CVE-2026-50647",
          "CVE-2026-50648",
          "CVE-2026-50649",
          "CVE-2026-50650",
          "CVE-2026-50652",
          "CVE-2026-50653",
          "CVE-2026-50659"
        ],
        "details": [
          {
            "id": "CVE-2026-47302",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01029,
            "epssPercentile": 0.61433,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47304",
            "title": ".NET Security Feature Bypass Vulnerability",
            "summary": "Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00216,
            "epssPercentile": 0.1193,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50304",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50324",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00855,
            "epssPercentile": 0.5598,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50355",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50368",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50411",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50525",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00604,
            "epssPercentile": 0.46716,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50527",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50646",
            "title": ".NET Framework Remote Code Execution Vulnerability",
            "summary": "Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00969,
            "epssPercentile": 0.59587,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50647",
            "title": "Active Directory Federation Server Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50648",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50649",
            "title": ".NET Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00938,
            "epssPercentile": 0.58565,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50650",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00296,
            "epssPercentile": 0.21888,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50652",
            "title": "Azure Active Directory Denial of Service Vulnerability",
            "summary": "Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0173,
            "epssPercentile": 0.76079,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50653",
            "title": "Azure Active Directory Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50659",
            "title": ".NET Spoofing Vulnerability",
            "summary": "Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0055,
            "epssPercentile": 0.44029,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-47304",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-developer-tools-kb5101006",
      "slug": "microsoft-2026-07-developer-tools-kb5101006",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5101006",
      "title": "Deploy Microsoft Developer Tools security update KB5101006",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5101006",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for x64-based Systems, plus 3 more",
      "platform": "Developer Tools",
      "release_version": "2.0.50727.9182 & 3.0.30729.9168 & 4.8.4803.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 17 linked CVEs for Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for x64-based Systems, plus 3 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 17,
        "ids": [
          "CVE-2026-47302",
          "CVE-2026-47304",
          "CVE-2026-50304",
          "CVE-2026-50324",
          "CVE-2026-50355",
          "CVE-2026-50368",
          "CVE-2026-50411",
          "CVE-2026-50525",
          "CVE-2026-50527",
          "CVE-2026-50646",
          "CVE-2026-50647",
          "CVE-2026-50648",
          "CVE-2026-50649",
          "CVE-2026-50650",
          "CVE-2026-50652",
          "CVE-2026-50653",
          "CVE-2026-50659"
        ],
        "details": [
          {
            "id": "CVE-2026-47302",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01029,
            "epssPercentile": 0.61433,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47304",
            "title": ".NET Security Feature Bypass Vulnerability",
            "summary": "Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00216,
            "epssPercentile": 0.1193,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50304",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50324",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00855,
            "epssPercentile": 0.5598,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50355",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50368",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50411",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50525",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00604,
            "epssPercentile": 0.46716,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50527",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50646",
            "title": ".NET Framework Remote Code Execution Vulnerability",
            "summary": "Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00969,
            "epssPercentile": 0.59587,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50647",
            "title": "Active Directory Federation Server Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50648",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50649",
            "title": ".NET Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00938,
            "epssPercentile": 0.58565,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50650",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00296,
            "epssPercentile": 0.21888,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50652",
            "title": "Azure Active Directory Denial of Service Vulnerability",
            "summary": "Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0173,
            "epssPercentile": 0.76079,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50653",
            "title": "Azure Active Directory Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50659",
            "title": ".NET Spoofing Vulnerability",
            "summary": "Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0055,
            "epssPercentile": 0.44029,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-47304",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-developer-tools-kb5101007",
      "slug": "microsoft-2026-07-developer-tools-kb5101007",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5101007",
      "title": "Deploy Microsoft Developer Tools security update KB5101007",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5101007",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 4.8 on Windows Server 2016, plus 1 more",
      "platform": "Developer Tools",
      "release_version": "4.8.4803.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 17 linked CVEs for Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 4.8 on Windows Server 2016, plus 1 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 17,
        "ids": [
          "CVE-2026-47302",
          "CVE-2026-47304",
          "CVE-2026-50304",
          "CVE-2026-50324",
          "CVE-2026-50355",
          "CVE-2026-50368",
          "CVE-2026-50411",
          "CVE-2026-50525",
          "CVE-2026-50527",
          "CVE-2026-50646",
          "CVE-2026-50647",
          "CVE-2026-50648",
          "CVE-2026-50649",
          "CVE-2026-50650",
          "CVE-2026-50652",
          "CVE-2026-50653",
          "CVE-2026-50659"
        ],
        "details": [
          {
            "id": "CVE-2026-47302",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01029,
            "epssPercentile": 0.61433,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47304",
            "title": ".NET Security Feature Bypass Vulnerability",
            "summary": "Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00216,
            "epssPercentile": 0.1193,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50304",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50324",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00855,
            "epssPercentile": 0.5598,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50355",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50368",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50411",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50525",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00604,
            "epssPercentile": 0.46716,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50527",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50646",
            "title": ".NET Framework Remote Code Execution Vulnerability",
            "summary": "Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00969,
            "epssPercentile": 0.59587,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50647",
            "title": "Active Directory Federation Server Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50648",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50649",
            "title": ".NET Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00938,
            "epssPercentile": 0.58565,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50650",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00296,
            "epssPercentile": 0.21888,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50652",
            "title": "Azure Active Directory Denial of Service Vulnerability",
            "summary": "Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0173,
            "epssPercentile": 0.76079,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50653",
            "title": "Azure Active Directory Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50659",
            "title": ".NET Spoofing Vulnerability",
            "summary": "Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0055,
            "epssPercentile": 0.44029,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-47304",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-developer-tools-kb5101008",
      "slug": "microsoft-2026-07-developer-tools-kb5101008",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5101008",
      "title": "Deploy Microsoft Developer Tools security update KB5101008",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5101008",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for x64-based Systems, plus 2 more",
      "platform": "Developer Tools",
      "release_version": "2.0.50727.9069 & 3.0.30729.9067 & 4.8.4803.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 17 linked CVEs for Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for x64-based Systems, plus 2 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 17,
        "ids": [
          "CVE-2026-47302",
          "CVE-2026-47304",
          "CVE-2026-50304",
          "CVE-2026-50324",
          "CVE-2026-50355",
          "CVE-2026-50368",
          "CVE-2026-50411",
          "CVE-2026-50525",
          "CVE-2026-50527",
          "CVE-2026-50646",
          "CVE-2026-50647",
          "CVE-2026-50648",
          "CVE-2026-50649",
          "CVE-2026-50650",
          "CVE-2026-50652",
          "CVE-2026-50653",
          "CVE-2026-50659"
        ],
        "details": [
          {
            "id": "CVE-2026-47302",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01029,
            "epssPercentile": 0.61433,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47304",
            "title": ".NET Security Feature Bypass Vulnerability",
            "summary": "Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00216,
            "epssPercentile": 0.1193,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50304",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50324",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00855,
            "epssPercentile": 0.5598,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50355",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50368",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50411",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50525",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00604,
            "epssPercentile": 0.46716,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50527",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50646",
            "title": ".NET Framework Remote Code Execution Vulnerability",
            "summary": "Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00969,
            "epssPercentile": 0.59587,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50647",
            "title": "Active Directory Federation Server Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50648",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50649",
            "title": ".NET Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00938,
            "epssPercentile": 0.58565,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50650",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00296,
            "epssPercentile": 0.21888,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50652",
            "title": "Azure Active Directory Denial of Service Vulnerability",
            "summary": "Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0173,
            "epssPercentile": 0.76079,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50653",
            "title": "Azure Active Directory Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50659",
            "title": ".NET Spoofing Vulnerability",
            "summary": "Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0055,
            "epssPercentile": 0.44029,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-47304",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-developer-tools-kb5101009",
      "slug": "microsoft-2026-07-developer-tools-kb5101009",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5101009",
      "title": "Deploy Microsoft Developer Tools security update KB5101009",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5101009",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft .NET Framework 4.8 on Windows Server 2012, Microsoft .NET Framework 4.8 on Windows Server 2012 (Server Core installation)",
      "platform": "Developer Tools",
      "release_version": "4.8.4803.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 17 linked CVEs for Microsoft .NET Framework 4.8 on Windows Server 2012, Microsoft .NET Framework 4.8 on Windows Server 2012 (Server Core installation).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 17,
        "ids": [
          "CVE-2026-47302",
          "CVE-2026-47304",
          "CVE-2026-50304",
          "CVE-2026-50324",
          "CVE-2026-50355",
          "CVE-2026-50368",
          "CVE-2026-50411",
          "CVE-2026-50525",
          "CVE-2026-50527",
          "CVE-2026-50646",
          "CVE-2026-50647",
          "CVE-2026-50648",
          "CVE-2026-50649",
          "CVE-2026-50650",
          "CVE-2026-50652",
          "CVE-2026-50653",
          "CVE-2026-50659"
        ],
        "details": [
          {
            "id": "CVE-2026-47302",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01029,
            "epssPercentile": 0.61433,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47304",
            "title": ".NET Security Feature Bypass Vulnerability",
            "summary": "Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00216,
            "epssPercentile": 0.1193,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50304",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50324",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00855,
            "epssPercentile": 0.5598,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50355",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50368",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50411",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50525",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00604,
            "epssPercentile": 0.46716,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50527",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50646",
            "title": ".NET Framework Remote Code Execution Vulnerability",
            "summary": "Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00969,
            "epssPercentile": 0.59587,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50647",
            "title": "Active Directory Federation Server Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50648",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50649",
            "title": ".NET Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00938,
            "epssPercentile": 0.58565,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50650",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00296,
            "epssPercentile": 0.21888,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50652",
            "title": "Azure Active Directory Denial of Service Vulnerability",
            "summary": "Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0173,
            "epssPercentile": 0.76079,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50653",
            "title": "Azure Active Directory Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50659",
            "title": ".NET Spoofing Vulnerability",
            "summary": "Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0055,
            "epssPercentile": 0.44029,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-47304",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-developer-tools-kb5101010",
      "slug": "microsoft-2026-07-developer-tools-kb5101010",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5101010",
      "title": "Deploy Microsoft Developer Tools security update KB5101010",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5101010",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022, Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022 (Server Core installation)",
      "platform": "Developer Tools",
      "release_version": "2.0.50727.9182 & 3.0.30729.9168 & 4.8.4803.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 17 linked CVEs for Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022, Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022 (Server Core installation).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 17,
        "ids": [
          "CVE-2026-47302",
          "CVE-2026-47304",
          "CVE-2026-50304",
          "CVE-2026-50324",
          "CVE-2026-50355",
          "CVE-2026-50368",
          "CVE-2026-50411",
          "CVE-2026-50525",
          "CVE-2026-50527",
          "CVE-2026-50646",
          "CVE-2026-50647",
          "CVE-2026-50648",
          "CVE-2026-50649",
          "CVE-2026-50650",
          "CVE-2026-50652",
          "CVE-2026-50653",
          "CVE-2026-50659"
        ],
        "details": [
          {
            "id": "CVE-2026-47302",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01029,
            "epssPercentile": 0.61433,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47304",
            "title": ".NET Security Feature Bypass Vulnerability",
            "summary": "Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00216,
            "epssPercentile": 0.1193,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50304",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50324",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00855,
            "epssPercentile": 0.5598,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50355",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50368",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50411",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50525",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00604,
            "epssPercentile": 0.46716,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50527",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50646",
            "title": ".NET Framework Remote Code Execution Vulnerability",
            "summary": "Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00969,
            "epssPercentile": 0.59587,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50647",
            "title": "Active Directory Federation Server Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50648",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50649",
            "title": ".NET Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00938,
            "epssPercentile": 0.58565,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50650",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00296,
            "epssPercentile": 0.21888,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50652",
            "title": "Azure Active Directory Denial of Service Vulnerability",
            "summary": "Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0173,
            "epssPercentile": 0.76079,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50653",
            "title": "Azure Active Directory Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50659",
            "title": ".NET Spoofing Vulnerability",
            "summary": "Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0055,
            "epssPercentile": 0.44029,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-47304",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-developer-tools-kb5101011",
      "slug": "microsoft-2026-07-developer-tools-kb5101011",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5101011",
      "title": "Deploy Microsoft Developer Tools security update KB5101011",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5101011",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft .NET Framework 4.8 on Windows Server 2012 R2, Microsoft .NET Framework 4.8 on Windows Server 2012 R2 (Server Core installation)",
      "platform": "Developer Tools",
      "release_version": "4.8.4803.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 17 linked CVEs for Microsoft .NET Framework 4.8 on Windows Server 2012 R2, Microsoft .NET Framework 4.8 on Windows Server 2012 R2 (Server Core installation).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 17,
        "ids": [
          "CVE-2026-47302",
          "CVE-2026-47304",
          "CVE-2026-50304",
          "CVE-2026-50324",
          "CVE-2026-50355",
          "CVE-2026-50368",
          "CVE-2026-50411",
          "CVE-2026-50525",
          "CVE-2026-50527",
          "CVE-2026-50646",
          "CVE-2026-50647",
          "CVE-2026-50648",
          "CVE-2026-50649",
          "CVE-2026-50650",
          "CVE-2026-50652",
          "CVE-2026-50653",
          "CVE-2026-50659"
        ],
        "details": [
          {
            "id": "CVE-2026-47302",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01029,
            "epssPercentile": 0.61433,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47304",
            "title": ".NET Security Feature Bypass Vulnerability",
            "summary": "Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00216,
            "epssPercentile": 0.1193,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50304",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50324",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00855,
            "epssPercentile": 0.5598,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50355",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50368",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50411",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50525",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00604,
            "epssPercentile": 0.46716,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50527",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50646",
            "title": ".NET Framework Remote Code Execution Vulnerability",
            "summary": "Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00969,
            "epssPercentile": 0.59587,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50647",
            "title": "Active Directory Federation Server Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50648",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50649",
            "title": ".NET Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00938,
            "epssPercentile": 0.58565,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50650",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00296,
            "epssPercentile": 0.21888,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50652",
            "title": "Azure Active Directory Denial of Service Vulnerability",
            "summary": "Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0173,
            "epssPercentile": 0.76079,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50653",
            "title": "Azure Active Directory Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50659",
            "title": ".NET Spoofing Vulnerability",
            "summary": "Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0055,
            "epssPercentile": 0.44029,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-47304",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-developer-tools-kb5101014",
      "slug": "microsoft-2026-07-developer-tools-kb5101014",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5101014",
      "title": "Deploy Microsoft Developer Tools security update KB5101014",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5101014",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 26H1 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 version 26H1 for x64-based Systems, Microsoft .NET Framework 3.5 on Windows 11 Version 26H1 for ARM64-based Systems, plus 1 more",
      "platform": "Developer Tools",
      "release_version": "2.0.50727.9182 & 3.0.30729.9168",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 11 linked CVEs for Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 26H1 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 version 26H1 for x64-based Systems, Microsoft .NET Framework 3.5 on Windows 11 Version 26H1 for ARM64-based Systems, plus 1 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 11,
        "ids": [
          "CVE-2026-47302",
          "CVE-2026-47304",
          "CVE-2026-50525",
          "CVE-2026-50527",
          "CVE-2026-50646",
          "CVE-2026-50648",
          "CVE-2026-50649",
          "CVE-2026-50650",
          "CVE-2026-50652",
          "CVE-2026-50653",
          "CVE-2026-50659"
        ],
        "details": [
          {
            "id": "CVE-2026-47302",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01029,
            "epssPercentile": 0.61433,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47304",
            "title": ".NET Security Feature Bypass Vulnerability",
            "summary": "Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00216,
            "epssPercentile": 0.1193,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50525",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00604,
            "epssPercentile": 0.46716,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50527",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50646",
            "title": ".NET Framework Remote Code Execution Vulnerability",
            "summary": "Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00969,
            "epssPercentile": 0.59587,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50648",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50649",
            "title": ".NET Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00938,
            "epssPercentile": 0.58565,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50650",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00296,
            "epssPercentile": 0.21888,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50652",
            "title": "Azure Active Directory Denial of Service Vulnerability",
            "summary": "Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0173,
            "epssPercentile": 0.76079,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50653",
            "title": "Azure Active Directory Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50659",
            "title": ".NET Spoofing Vulnerability",
            "summary": "Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0055,
            "epssPercentile": 0.44029,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-47304",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-developer-tools-kb5104032",
      "slug": "microsoft-2026-07-developer-tools-kb5104032",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5104032",
      "title": "Deploy Microsoft Developer Tools security update KB5104032",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5104032",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": ".NET 8.0 installed on Linux, .NET 8.0 installed on Mac OS, .NET 8.0 installed on Windows",
      "platform": "Developer Tools",
      "release_version": "8.0.29",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 17 linked CVEs for .NET 8.0 installed on Linux, .NET 8.0 installed on Mac OS, .NET 8.0 installed on Windows.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 17,
        "ids": [
          "CVE-2026-47300",
          "CVE-2026-47302",
          "CVE-2026-47303",
          "CVE-2026-47304",
          "CVE-2026-50524",
          "CVE-2026-50525",
          "CVE-2026-50526",
          "CVE-2026-50527",
          "CVE-2026-50528",
          "CVE-2026-50646",
          "CVE-2026-50648",
          "CVE-2026-50649",
          "CVE-2026-50650",
          "CVE-2026-50651",
          "CVE-2026-50659",
          "CVE-2026-56170",
          "CVE-2026-57108"
        ],
        "details": [
          {
            "id": "CVE-2026-47300",
            "title": "ASP.NET Core Elevation of Privilege Vulnerability",
            "summary": "Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00527,
            "epssPercentile": 0.42735,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47302",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01029,
            "epssPercentile": 0.61433,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47303",
            "title": "ASP.NET Core Elevation of Privilege Vulnerability",
            "summary": "Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00736,
            "epssPercentile": 0.52127,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47304",
            "title": ".NET Security Feature Bypass Vulnerability",
            "summary": "Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00216,
            "epssPercentile": 0.1193,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50524",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00634,
            "epssPercentile": 0.48116,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50525",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00604,
            "epssPercentile": 0.46716,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50526",
            "title": ".NET Tampering Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00228,
            "epssPercentile": 0.13434,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50527",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50528",
            "title": ".NET Security Feature Bypass Vulnerability",
            "summary": "Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 8.2,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00563,
            "epssPercentile": 0.44732,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50646",
            "title": ".NET Framework Remote Code Execution Vulnerability",
            "summary": "Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00969,
            "epssPercentile": 0.59587,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50648",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50649",
            "title": ".NET Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00938,
            "epssPercentile": 0.58565,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50650",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00296,
            "epssPercentile": 0.21888,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50651",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50659",
            "title": ".NET Spoofing Vulnerability",
            "summary": "Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0055,
            "epssPercentile": 0.44029,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56170",
            "title": "ASP.NET Core Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01008,
            "epssPercentile": 0.60787,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57108",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01105,
            "epssPercentile": 0.63619,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-47303",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-developer-tools-kb5104033",
      "slug": "microsoft-2026-07-developer-tools-kb5104033",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5104033",
      "title": "Deploy Microsoft Developer Tools security update KB5104033",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5104033",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": ".NET 9.0 installed on Linux, .NET 9.0 installed on Mac OS, .NET 9.0 installed on Windows",
      "platform": "Developer Tools",
      "release_version": "9.0.18",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 17 linked CVEs for .NET 9.0 installed on Linux, .NET 9.0 installed on Mac OS, .NET 9.0 installed on Windows.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 17,
        "ids": [
          "CVE-2026-47300",
          "CVE-2026-47302",
          "CVE-2026-47303",
          "CVE-2026-47304",
          "CVE-2026-50524",
          "CVE-2026-50525",
          "CVE-2026-50526",
          "CVE-2026-50527",
          "CVE-2026-50528",
          "CVE-2026-50646",
          "CVE-2026-50648",
          "CVE-2026-50649",
          "CVE-2026-50650",
          "CVE-2026-50651",
          "CVE-2026-50659",
          "CVE-2026-56170",
          "CVE-2026-57108"
        ],
        "details": [
          {
            "id": "CVE-2026-47300",
            "title": "ASP.NET Core Elevation of Privilege Vulnerability",
            "summary": "Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00527,
            "epssPercentile": 0.42735,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47302",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01029,
            "epssPercentile": 0.61433,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47303",
            "title": "ASP.NET Core Elevation of Privilege Vulnerability",
            "summary": "Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00736,
            "epssPercentile": 0.52127,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47304",
            "title": ".NET Security Feature Bypass Vulnerability",
            "summary": "Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00216,
            "epssPercentile": 0.1193,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50524",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00634,
            "epssPercentile": 0.48116,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50525",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00604,
            "epssPercentile": 0.46716,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50526",
            "title": ".NET Tampering Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00228,
            "epssPercentile": 0.13434,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50527",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50528",
            "title": ".NET Security Feature Bypass Vulnerability",
            "summary": "Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 8.2,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00563,
            "epssPercentile": 0.44732,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50646",
            "title": ".NET Framework Remote Code Execution Vulnerability",
            "summary": "Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00969,
            "epssPercentile": 0.59587,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50648",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50649",
            "title": ".NET Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00938,
            "epssPercentile": 0.58565,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50650",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00296,
            "epssPercentile": 0.21888,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50651",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50659",
            "title": ".NET Spoofing Vulnerability",
            "summary": "Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0055,
            "epssPercentile": 0.44029,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56170",
            "title": "ASP.NET Core Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01008,
            "epssPercentile": 0.60787,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57108",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01105,
            "epssPercentile": 0.63619,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-47303",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-developer-tools-kb5104034",
      "slug": "microsoft-2026-07-developer-tools-kb5104034",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5104034",
      "title": "Deploy Microsoft Developer Tools security update KB5104034",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5104034",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": ".NET 10.0 installed on Linux, .NET 10.0 installed on Mac OS, .NET 10.0 installed on Windows",
      "platform": "Developer Tools",
      "release_version": "10.0.10",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 14 linked CVEs for .NET 10.0 installed on Linux, .NET 10.0 installed on Mac OS, .NET 10.0 installed on Windows.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 14,
        "ids": [
          "CVE-2026-47300",
          "CVE-2026-47302",
          "CVE-2026-47303",
          "CVE-2026-47304",
          "CVE-2026-50524",
          "CVE-2026-50525",
          "CVE-2026-50526",
          "CVE-2026-50527",
          "CVE-2026-50528",
          "CVE-2026-50648",
          "CVE-2026-50651",
          "CVE-2026-50659",
          "CVE-2026-56170",
          "CVE-2026-57108"
        ],
        "details": [
          {
            "id": "CVE-2026-47300",
            "title": "ASP.NET Core Elevation of Privilege Vulnerability",
            "summary": "Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00527,
            "epssPercentile": 0.42735,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47302",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01029,
            "epssPercentile": 0.61433,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47303",
            "title": "ASP.NET Core Elevation of Privilege Vulnerability",
            "summary": "Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00736,
            "epssPercentile": 0.52127,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47304",
            "title": ".NET Security Feature Bypass Vulnerability",
            "summary": "Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00216,
            "epssPercentile": 0.1193,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50524",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00634,
            "epssPercentile": 0.48116,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50525",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00604,
            "epssPercentile": 0.46716,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50526",
            "title": ".NET Tampering Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00228,
            "epssPercentile": 0.13434,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50527",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50528",
            "title": ".NET Security Feature Bypass Vulnerability",
            "summary": "Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 8.2,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00563,
            "epssPercentile": 0.44732,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50648",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50651",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50659",
            "title": ".NET Spoofing Vulnerability",
            "summary": "Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0055,
            "epssPercentile": 0.44029,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56170",
            "title": "ASP.NET Core Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01008,
            "epssPercentile": 0.60787,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57108",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01105,
            "epssPercentile": 0.63619,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-47303",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-developer-tools-msrc-2026-07-developer-tools-release-notes-visual-studio-code",
      "slug": "microsoft-2026-07-developer-tools-msrc-2026-07-developer-tools-release-notes-visual-studio-code",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-07-developer-tools-release-notes",
      "title": "Deploy Microsoft Developer Tools update for Visual Studio Code",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://code.visualstudio.com/Download",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Visual Studio Code",
      "platform": "Developer Tools",
      "release_version": "1.128.1",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 6 linked CVEs for Visual Studio Code.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 6,
        "ids": [
          "CVE-2026-41109",
          "CVE-2026-45496",
          "CVE-2026-47282",
          "CVE-2026-50520",
          "CVE-2026-57101",
          "CVE-2026-57102"
        ],
        "details": [
          {
            "id": "CVE-2026-41109",
            "title": "GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability",
            "summary": "Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00861,
            "epssPercentile": 0.56169,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-45496",
            "title": "Visual Studio Code Security Feature Bypass Vulnerability",
            "summary": "Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00475,
            "epssPercentile": 0.39401,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47282",
            "title": "GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability",
            "summary": "Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00874,
            "epssPercentile": 0.5659,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50520",
            "title": "Visual Studio Code Remote Code Execution Vulnerability",
            "summary": "Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00352,
            "epssPercentile": 0.2824,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57101",
            "title": "Visual Studio Code Security Feature Bypass Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00482,
            "epssPercentile": 0.3987,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57102",
            "title": "Visual Studio Code Security Feature Bypass Vulnerability",
            "summary": "Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.5486,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-57102",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-developer-tools-msrc-2026-07-developer-tools-release-notes-microsoft-aspnet-odata",
      "slug": "microsoft-2026-07-developer-tools-msrc-2026-07-developer-tools-release-notes-microsoft-aspnet-odata",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-07-developer-tools-release-notes",
      "title": "Deploy Microsoft Developer Tools update for Microsoft.AspNet.OData",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://msrc.microsoft.com/update-guide/releaseNote/2026-Jul",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft.AspNet.OData",
      "platform": "Developer Tools",
      "release_version": "7.8.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Microsoft.AspNet.OData.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 2,
        "ids": [
          "CVE-2026-45646",
          "CVE-2026-50506"
        ],
        "details": [
          {
            "id": "CVE-2026-45646",
            "title": "OData for ASP.NET and ASP.NET Core Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65473,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50506",
            "title": "OData for ASP.NET and ASP.NET Core Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.5,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-50506",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-developer-tools-msrc-2026-07-developer-tools-release-notes-microsoft-aspnetcore-odata",
      "slug": "microsoft-2026-07-developer-tools-msrc-2026-07-developer-tools-release-notes-microsoft-aspnetcore-odata",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-07-developer-tools-release-notes",
      "title": "Deploy Microsoft Developer Tools update for Microsoft.AspNetCore.OData",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://msrc.microsoft.com/update-guide/releaseNote/2026-Jul",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft.AspNetCore.OData",
      "platform": "Developer Tools",
      "release_version": "9.5.0[SX1]",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Microsoft.AspNetCore.OData.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 2,
        "ids": [
          "CVE-2026-45646",
          "CVE-2026-50506"
        ],
        "details": [
          {
            "id": "CVE-2026-45646",
            "title": "OData for ASP.NET and ASP.NET Core Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65473,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50506",
            "title": "OData for ASP.NET and ASP.NET Core Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.5,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-50506",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-developer-tools-msrc-2026-07-developer-tools-release-notes-microsoft-visual-studio-2022-version-17-12",
      "slug": "microsoft-2026-07-developer-tools-msrc-2026-07-developer-tools-release-notes-microsoft-visual-studio-2022-version-17-12",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-07-developer-tools-release-notes",
      "title": "Deploy Microsoft Developer Tools update for Microsoft Visual Studio 2022 version 17.12",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.12",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft Visual Studio 2022 version 17.12",
      "platform": "Developer Tools",
      "release_version": "17.12.22",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 15 linked CVEs for Microsoft Visual Studio 2022 version 17.12.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 15,
        "ids": [
          "CVE-2026-47300",
          "CVE-2026-47302",
          "CVE-2026-47303",
          "CVE-2026-47304",
          "CVE-2026-47305",
          "CVE-2026-50524",
          "CVE-2026-50525",
          "CVE-2026-50526",
          "CVE-2026-50527",
          "CVE-2026-50528",
          "CVE-2026-50646",
          "CVE-2026-50648",
          "CVE-2026-50650",
          "CVE-2026-50651",
          "CVE-2026-50659"
        ],
        "details": [
          {
            "id": "CVE-2026-47300",
            "title": "ASP.NET Core Elevation of Privilege Vulnerability",
            "summary": "Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00527,
            "epssPercentile": 0.42735,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47302",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01029,
            "epssPercentile": 0.61433,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47303",
            "title": "ASP.NET Core Elevation of Privilege Vulnerability",
            "summary": "Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00736,
            "epssPercentile": 0.52127,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47304",
            "title": ".NET Security Feature Bypass Vulnerability",
            "summary": "Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00216,
            "epssPercentile": 0.1193,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47305",
            "title": "Visual Studio Remote Code Execution Vulnerability",
            "summary": "Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.388,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50524",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00634,
            "epssPercentile": 0.48116,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50525",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00604,
            "epssPercentile": 0.46716,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50526",
            "title": ".NET Tampering Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00228,
            "epssPercentile": 0.13434,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50527",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50528",
            "title": ".NET Security Feature Bypass Vulnerability",
            "summary": "Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 8.2,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00563,
            "epssPercentile": 0.44732,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50646",
            "title": ".NET Framework Remote Code Execution Vulnerability",
            "summary": "Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00969,
            "epssPercentile": 0.59587,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50648",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50650",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00296,
            "epssPercentile": 0.21888,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50651",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50659",
            "title": ".NET Spoofing Vulnerability",
            "summary": "Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0055,
            "epssPercentile": 0.44029,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-47303",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-developer-tools-msrc-2026-07-developer-tools-release-notes-microsoft-visual-studio-2022-version-17-14",
      "slug": "microsoft-2026-07-developer-tools-msrc-2026-07-developer-tools-release-notes-microsoft-visual-studio-2022-version-17-14",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-07-developer-tools-release-notes",
      "title": "Deploy Microsoft Developer Tools update for Microsoft Visual Studio 2022 version 17.14",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.14",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft Visual Studio 2022 version 17.14",
      "platform": "Developer Tools",
      "release_version": "17.14.36",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 15 linked CVEs for Microsoft Visual Studio 2022 version 17.14.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 15,
        "ids": [
          "CVE-2026-47300",
          "CVE-2026-47302",
          "CVE-2026-47303",
          "CVE-2026-47304",
          "CVE-2026-47305",
          "CVE-2026-50524",
          "CVE-2026-50525",
          "CVE-2026-50526",
          "CVE-2026-50527",
          "CVE-2026-50528",
          "CVE-2026-50646",
          "CVE-2026-50648",
          "CVE-2026-50650",
          "CVE-2026-50651",
          "CVE-2026-50659"
        ],
        "details": [
          {
            "id": "CVE-2026-47300",
            "title": "ASP.NET Core Elevation of Privilege Vulnerability",
            "summary": "Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00527,
            "epssPercentile": 0.42735,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47302",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01029,
            "epssPercentile": 0.61433,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47303",
            "title": "ASP.NET Core Elevation of Privilege Vulnerability",
            "summary": "Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00736,
            "epssPercentile": 0.52127,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47304",
            "title": ".NET Security Feature Bypass Vulnerability",
            "summary": "Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00216,
            "epssPercentile": 0.1193,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47305",
            "title": "Visual Studio Remote Code Execution Vulnerability",
            "summary": "Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.388,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50524",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00634,
            "epssPercentile": 0.48116,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50525",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00604,
            "epssPercentile": 0.46716,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50526",
            "title": ".NET Tampering Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00228,
            "epssPercentile": 0.13434,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50527",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50528",
            "title": ".NET Security Feature Bypass Vulnerability",
            "summary": "Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 8.2,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00563,
            "epssPercentile": 0.44732,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50646",
            "title": ".NET Framework Remote Code Execution Vulnerability",
            "summary": "Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00969,
            "epssPercentile": 0.59587,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50648",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50650",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00296,
            "epssPercentile": 0.21888,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50651",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50659",
            "title": ".NET Spoofing Vulnerability",
            "summary": "Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0055,
            "epssPercentile": 0.44029,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-47303",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-developer-tools-msrc-2026-07-developer-tools-release-notes-microsoft-visual-studio-2026-version-18-7",
      "slug": "microsoft-2026-07-developer-tools-msrc-2026-07-developer-tools-release-notes-microsoft-visual-studio-2026-version-18-7",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-07-developer-tools-release-notes",
      "title": "Deploy Microsoft Developer Tools update for Microsoft Visual Studio 2026 version 18.7",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://my.visualstudio.com/Downloads?q=Visual Studio 2026 version 18.7",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft Visual Studio 2026 version 18.7",
      "platform": "Developer Tools",
      "release_version": "18.7.4",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 16 linked CVEs for Microsoft Visual Studio 2026 version 18.7.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 16,
        "ids": [
          "CVE-2026-47300",
          "CVE-2026-47302",
          "CVE-2026-47303",
          "CVE-2026-47304",
          "CVE-2026-47305",
          "CVE-2026-50524",
          "CVE-2026-50525",
          "CVE-2026-50526",
          "CVE-2026-50527",
          "CVE-2026-50528",
          "CVE-2026-50646",
          "CVE-2026-50648",
          "CVE-2026-50649",
          "CVE-2026-50650",
          "CVE-2026-50651",
          "CVE-2026-50659"
        ],
        "details": [
          {
            "id": "CVE-2026-47300",
            "title": "ASP.NET Core Elevation of Privilege Vulnerability",
            "summary": "Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00527,
            "epssPercentile": 0.42735,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47302",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01029,
            "epssPercentile": 0.61433,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47303",
            "title": "ASP.NET Core Elevation of Privilege Vulnerability",
            "summary": "Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00736,
            "epssPercentile": 0.52127,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47304",
            "title": ".NET Security Feature Bypass Vulnerability",
            "summary": "Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00216,
            "epssPercentile": 0.1193,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47305",
            "title": "Visual Studio Remote Code Execution Vulnerability",
            "summary": "Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.388,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50524",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00634,
            "epssPercentile": 0.48116,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50525",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00604,
            "epssPercentile": 0.46716,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50526",
            "title": ".NET Tampering Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00228,
            "epssPercentile": 0.13434,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50527",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50528",
            "title": ".NET Security Feature Bypass Vulnerability",
            "summary": "Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 8.2,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00563,
            "epssPercentile": 0.44732,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50646",
            "title": ".NET Framework Remote Code Execution Vulnerability",
            "summary": "Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00969,
            "epssPercentile": 0.59587,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50648",
            "title": ".NET Framework Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50649",
            "title": ".NET Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00938,
            "epssPercentile": 0.58565,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50650",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00296,
            "epssPercentile": 0.21888,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50651",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55515,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50659",
            "title": ".NET Spoofing Vulnerability",
            "summary": "Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0055,
            "epssPercentile": 0.44029,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-47303",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-esu-kb5094041",
      "slug": "microsoft-2026-07-esu-kb5094041",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5094041",
      "title": "Deploy Microsoft ESU security update KB5094041",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5094041",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)",
      "platform": "ESU",
      "release_version": "6.3.9600.23228",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 2,
        "ids": [
          "CVE-2026-42990",
          "CVE-2026-48564"
        ],
        "details": [
          {
            "id": "CVE-2026-42990",
            "title": "SQL Server ODBC driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59786,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48564",
            "title": "DHCP Server Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.5779,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-42990",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-esu-kb5094042",
      "slug": "microsoft-2026-07-esu-kb5094042",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5094042",
      "title": "Deploy Microsoft ESU security update KB5094042",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5094042",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Windows Server 2012, Windows Server 2012 (Server Core installation)",
      "platform": "ESU",
      "release_version": "6.2.9200.26132",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Windows Server 2012, Windows Server 2012 (Server Core installation).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 2,
        "ids": [
          "CVE-2026-42990",
          "CVE-2026-48564"
        ],
        "details": [
          {
            "id": "CVE-2026-42990",
            "title": "SQL Server ODBC driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59786,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48564",
            "title": "DHCP Server Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.5779,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-42990",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-esu-kb5099415",
      "slug": "microsoft-2026-07-esu-kb5099415",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5099415",
      "title": "Deploy Microsoft ESU security update KB5099415",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5099415",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, plus 1 more",
      "platform": "ESU",
      "release_version": "1.000",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows Server 2012, Windows Server 2012 (Server Core installation), Windows Server 2012 R2, plus 1 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-50480"
        ],
        "details": [
          {
            "id": "CVE-2026-50480",
            "title": "Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26097,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-50480",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-esu-kb5099444",
      "slug": "microsoft-2026-07-esu-kb5099444",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5099444",
      "title": "Deploy Microsoft ESU security update KB5099444",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5099444",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)",
      "platform": "ESU",
      "release_version": "6.3.9600.23291",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 184 linked CVEs for Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation). Microsoft reports exploitation for CVE-2026-56155.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 184,
        "ids": [
          "CVE-2026-33842",
          "CVE-2026-34346",
          "CVE-2026-40378",
          "CVE-2026-40400",
          "CVE-2026-42975",
          "CVE-2026-44806",
          "CVE-2026-49164",
          "CVE-2026-49177",
          "CVE-2026-49178",
          "CVE-2026-49180",
          "CVE-2026-49181",
          "CVE-2026-49184",
          "CVE-2026-49789",
          "CVE-2026-49790",
          "CVE-2026-49791",
          "CVE-2026-49794",
          "CVE-2026-49796",
          "CVE-2026-49797",
          "CVE-2026-49798",
          "CVE-2026-49799",
          "CVE-2026-49801",
          "CVE-2026-49803",
          "CVE-2026-49804",
          "CVE-2026-49805",
          "CVE-2026-50294",
          "CVE-2026-50297",
          "CVE-2026-50298",
          "CVE-2026-50299",
          "CVE-2026-50304",
          "CVE-2026-50306",
          "CVE-2026-50308",
          "CVE-2026-50309",
          "CVE-2026-50311",
          "CVE-2026-50312",
          "CVE-2026-50313",
          "CVE-2026-50321",
          "CVE-2026-50324",
          "CVE-2026-50325",
          "CVE-2026-50328",
          "CVE-2026-50330",
          "CVE-2026-50332",
          "CVE-2026-50334",
          "CVE-2026-50341",
          "CVE-2026-50344",
          "CVE-2026-50346",
          "CVE-2026-50347",
          "CVE-2026-50351",
          "CVE-2026-50352",
          "CVE-2026-50355",
          "CVE-2026-50359",
          "CVE-2026-50363",
          "CVE-2026-50365",
          "CVE-2026-50366",
          "CVE-2026-50368",
          "CVE-2026-50369",
          "CVE-2026-50370",
          "CVE-2026-50371",
          "CVE-2026-50372",
          "CVE-2026-50376",
          "CVE-2026-50380",
          "CVE-2026-50386",
          "CVE-2026-50387",
          "CVE-2026-50388",
          "CVE-2026-50390",
          "CVE-2026-50391",
          "CVE-2026-50394",
          "CVE-2026-50397",
          "CVE-2026-50400",
          "CVE-2026-50402",
          "CVE-2026-50405",
          "CVE-2026-50411",
          "CVE-2026-50412",
          "CVE-2026-50417",
          "CVE-2026-50419",
          "CVE-2026-50422",
          "CVE-2026-50426",
          "CVE-2026-50431",
          "CVE-2026-50433",
          "CVE-2026-50435",
          "CVE-2026-50439",
          "CVE-2026-50444",
          "CVE-2026-50445",
          "CVE-2026-50447",
          "CVE-2026-50448",
          "CVE-2026-50451",
          "CVE-2026-50453",
          "CVE-2026-50455",
          "CVE-2026-50456",
          "CVE-2026-50461",
          "CVE-2026-50462",
          "CVE-2026-50470",
          "CVE-2026-50471",
          "CVE-2026-50474",
          "CVE-2026-50475",
          "CVE-2026-50476",
          "CVE-2026-50477",
          "CVE-2026-50480",
          "CVE-2026-50482",
          "CVE-2026-50485",
          "CVE-2026-50489",
          "CVE-2026-50490",
          "CVE-2026-50491",
          "CVE-2026-50494",
          "CVE-2026-50496",
          "CVE-2026-50497",
          "CVE-2026-50498",
          "CVE-2026-50500",
          "CVE-2026-50502",
          "CVE-2026-50504",
          "CVE-2026-50505",
          "CVE-2026-50518",
          "CVE-2026-50647",
          "CVE-2026-50666",
          "CVE-2026-50667",
          "CVE-2026-50669",
          "CVE-2026-50673",
          "CVE-2026-50683",
          "CVE-2026-50684",
          "CVE-2026-50685",
          "CVE-2026-50686",
          "CVE-2026-50688",
          "CVE-2026-50690",
          "CVE-2026-50694",
          "CVE-2026-50695",
          "CVE-2026-50697",
          "CVE-2026-54107",
          "CVE-2026-54115",
          "CVE-2026-54119",
          "CVE-2026-54121",
          "CVE-2026-54122",
          "CVE-2026-54128",
          "CVE-2026-54982",
          "CVE-2026-54983",
          "CVE-2026-54987",
          "CVE-2026-54989",
          "CVE-2026-54992",
          "CVE-2026-54995",
          "CVE-2026-54997",
          "CVE-2026-54999",
          "CVE-2026-55003",
          "CVE-2026-55004",
          "CVE-2026-56155",
          "CVE-2026-56159",
          "CVE-2026-56175",
          "CVE-2026-56176",
          "CVE-2026-56182",
          "CVE-2026-56186",
          "CVE-2026-56188",
          "CVE-2026-56189",
          "CVE-2026-56190",
          "CVE-2026-56194",
          "CVE-2026-56647",
          "CVE-2026-56648",
          "CVE-2026-56649",
          "CVE-2026-56650",
          "CVE-2026-57083",
          "CVE-2026-57084",
          "CVE-2026-57085",
          "CVE-2026-57089",
          "CVE-2026-57092",
          "CVE-2026-57093",
          "CVE-2026-57095",
          "CVE-2026-57096",
          "CVE-2026-57097",
          "CVE-2026-57976",
          "CVE-2026-57979",
          "CVE-2026-57982",
          "CVE-2026-58531",
          "CVE-2026-58532",
          "CVE-2026-58533",
          "CVE-2026-58535",
          "CVE-2026-58539",
          "CVE-2026-58540",
          "CVE-2026-58545",
          "CVE-2026-58546",
          "CVE-2026-58594",
          "CVE-2026-58608",
          "CVE-2026-58609",
          "CVE-2026-58614",
          "CVE-2026-58627",
          "CVE-2026-58629",
          "CVE-2026-58637",
          "CVE-2026-58638",
          "CVE-2026-58640"
        ],
        "details": [
          {
            "id": "CVE-2026-33842",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39646,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-34346",
            "title": "Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability",
            "summary": "Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0027,
            "epssPercentile": 0.18916,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-40378",
            "title": "Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability",
            "summary": "Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65473,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-40400",
            "title": "Windows PowerShell Remote Code Execution Vulnerability",
            "summary": "Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00868,
            "epssPercentile": 0.56393,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-42975",
            "title": "Windows Bluetooth Port Driver Remote Code Execution",
            "summary": "Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00536,
            "epssPercentile": 0.43257,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-44806",
            "title": "Windows Secure Channel Denial of Service Vulnerability",
            "summary": "Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65471,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49164",
            "title": "Windows Active Directory Domain Services Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53952,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49177",
            "title": "Windows TCP/IP Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00443,
            "epssPercentile": 0.37172,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49178",
            "title": "Windows Active Directory Domain Services Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.57789,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49180",
            "title": "Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00444,
            "epssPercentile": 0.37219,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49181",
            "title": "Windows DHCP Client Elevation of Privilege Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01172,
            "epssPercentile": 0.65406,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49184",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00337,
            "epssPercentile": 0.26479,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49789",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29002,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49790",
            "title": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
            "summary": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29001,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49791",
            "title": "Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0038,
            "epssPercentile": 0.31138,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49794",
            "title": "Windows USB Audio Class Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00468,
            "epssPercentile": 0.3893,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49796",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49797",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38802,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49798",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.",
            "score": 9.3,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00364,
            "epssPercentile": 0.29518,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49799",
            "title": "Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability",
            "summary": "Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01138,
            "epssPercentile": 0.64468,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49801",
            "title": "Windows SMB Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33744,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49803",
            "title": "Windows AppX Deployment Extensions Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.1017,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49804",
            "title": "Windows USB Video Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows USB Video Driver allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00483,
            "epssPercentile": 0.39895,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49805",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00236,
            "epssPercentile": 0.14488,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50294",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized attacker to disclose information locally.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00506,
            "epssPercentile": 0.41392,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50297",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00236,
            "epssPercentile": 0.14488,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50298",
            "title": "Windows Spaceport.sys Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36765,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50299",
            "title": "Windows Storage Spaces Direct Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36764,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50304",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50306",
            "title": "Windows TCP/IP Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26104,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50308",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38802,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50309",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26104,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50311",
            "title": "Windows Server Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50312",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 4.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0035,
            "epssPercentile": 0.28037,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50313",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38794,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50321",
            "title": "Windows USB Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11649,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50324",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00855,
            "epssPercentile": 0.5598,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50325",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00236,
            "epssPercentile": 0.14488,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50328",
            "title": "Windows Server Update Service (WSUS) Tampering Vulnerability",
            "summary": "Uncaught exception in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01232,
            "epssPercentile": 0.67,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50330",
            "title": "Windows Remote Desktop Client Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01252,
            "epssPercentile": 0.6748,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50332",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50334",
            "title": "Windows Push Notification Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Notification allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39645,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50341",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33741,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50344",
            "title": "Windows OLE Elevation of Privilege Vulnerability",
            "summary": "Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50346",
            "title": "Netlogon RPC Elevation of Privilege Vulnerability",
            "summary": "Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50347",
            "title": "Windows Data.dll Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38792,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50351",
            "title": "Windows Audio Compression Manager (ACM) Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50352",
            "title": "Windows Cryptographic Services Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50355",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50359",
            "title": "Microsoft XML Core Services Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20051,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50363",
            "title": "Windows Push Notifications Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26102,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50365",
            "title": "Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability",
            "summary": "Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00542,
            "epssPercentile": 0.43604,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50366",
            "title": "Windows Active Directory Domain Services Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01138,
            "epssPercentile": 0.64468,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50368",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50369",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00701,
            "epssPercentile": 0.50891,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50370",
            "title": "DHCP Server Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00502,
            "epssPercentile": 0.41141,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50371",
            "title": "Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows LUAFV allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10167,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50372",
            "title": "Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability",
            "summary": "Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18081,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50376",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50380",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.",
            "score": 9.6,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.54859,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50386",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38791,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50387",
            "title": "Windows GDI Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26111,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50388",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38797,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50390",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20053,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50391",
            "title": "Windows Group Policy Elevation of Privilege Vulnerability",
            "summary": "Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.2211,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50394",
            "title": "Windows Media Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39643,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50397",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18081,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50400",
            "title": "Windows App Package Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.2611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50402",
            "title": "NTFS Elevation of Privilege Vulnerability",
            "summary": "Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.2611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50405",
            "title": "Windows Filtering Platform Elevation of Privilege Vulnerability",
            "summary": "Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50411",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50412",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50417",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26111,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50419",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.",
            "score": 3.3,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00458,
            "epssPercentile": 0.38211,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50422",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50426",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent network.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00558,
            "epssPercentile": 0.44441,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50431",
            "title": "Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability",
            "summary": "Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39648,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50433",
            "title": "Windows Media Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Media allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50435",
            "title": "Windows Overlay Filter Elevation of Privilege Vulnerability",
            "summary": "Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50439",
            "title": "Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53953,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50444",
            "title": "Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00778,
            "epssPercentile": 0.53532,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50445",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58032,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50447",
            "title": "Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59787,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50448",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38799,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50451",
            "title": "Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00307,
            "epssPercentile": 0.23134,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50453",
            "title": "Windows USB Audio Class Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0051,
            "epssPercentile": 0.41673,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50455",
            "title": "Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33743,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50456",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39646,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50461",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38801,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50462",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00457,
            "epssPercentile": 0.38194,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50470",
            "title": "Windows Network Policy Server SNMP Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01027,
            "epssPercentile": 0.61358,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50471",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38793,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50474",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.54859,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50475",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.00375,
            "epssPercentile": 0.30678,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Medium technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50476",
            "title": "Windows Network Connections Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Windows allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20051,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50477",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.261,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50480",
            "title": "Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26097,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50482",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29001,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50485",
            "title": "Windows Hyper-V Denial of Service Vulnerability",
            "summary": "Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.",
            "score": 4.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00656,
            "epssPercentile": 0.49112,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50489",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50490",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20054,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50491",
            "title": "Code Integrity DLL (ci.dll) Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20054,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50494",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26098,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50496",
            "title": "Windows Network Policy Server SNMP Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50497",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58032,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50498",
            "title": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
            "summary": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00363,
            "epssPercentile": 0.29377,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50500",
            "title": "Windows Netlogon Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00742,
            "epssPercentile": 0.52348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50502",
            "title": "Windows Event Logging Service Remote Code Execution Vulnerability",
            "summary": "Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00654,
            "epssPercentile": 0.49042,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50504",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.5803,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50505",
            "title": "Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00742,
            "epssPercentile": 0.52348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50518",
            "title": "Windows DHCP Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59786,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50647",
            "title": "Active Directory Federation Server Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50666",
            "title": "Windows Remote Access Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.5779,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50667",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11651,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50669",
            "title": "Windows Telephony Server Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.1017,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50673",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.1165,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50683",
            "title": "Windows DHCP Client Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00576,
            "epssPercentile": 0.45358,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50684",
            "title": "Active Directory Federation Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Active Directory Federation Services (AD FS) allows an authorized attacker to perform spoofing over a network.",
            "score": 4.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00395,
            "epssPercentile": 0.32825,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50685",
            "title": "Windows DHCP Server Remote Code Execution Vulnerability",
            "summary": "Double free in Windows DHCP Server allows an authorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00663,
            "epssPercentile": 0.49414,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50686",
            "title": "Windows OLE Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00707,
            "epssPercentile": 0.5113,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50688",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20053,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50690",
            "title": "Windows SMB Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50694",
            "title": "Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53953,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50695",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65468,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50697",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00395,
            "epssPercentile": 0.32743,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54107",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11651,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54115",
            "title": "Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26115,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54119",
            "title": "Windows Active Directory Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54121",
            "title": "Active Directory Certificate Services Elevation of Privilege Vulnerability",
            "summary": "Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01788,
            "epssPercentile": 0.76867,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54122",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00364,
            "epssPercentile": 0.29518,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54128",
            "title": "Windows DHCP Client Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00364,
            "epssPercentile": 0.29519,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54982",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00535,
            "epssPercentile": 0.43236,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54983",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65471,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54987",
            "title": "Windows Overlay Filter Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54989",
            "title": "Quality Windows Audio/Video Experience (QWAVE) Elevation of Privilege Vulnerability",
            "summary": "Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20052,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54992",
            "title": "Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00337,
            "epssPercentile": 0.26479,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54995",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53953,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54997",
            "title": "Windows SMB Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54999",
            "title": "Windows TCP/IP Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0041,
            "epssPercentile": 0.34281,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55003",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55004",
            "title": "Windows Print Configuration Elevation of Privilege Vulnerability",
            "summary": "Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56155",
            "title": "Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability",
            "summary": "Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2026-07-14.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00346,
            "epssPercentile": 0.27582,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2026-07-28 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56159",
            "title": "DHCP Server Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59787,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56175",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26112,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56176",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26112,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56182",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26112,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56186",
            "title": "Windows Secure Channel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01106,
            "epssPercentile": 0.63644,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56188",
            "title": "Windows Server Network driver Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00607,
            "epssPercentile": 0.46852,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56189",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00393,
            "epssPercentile": 0.32499,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56190",
            "title": "Remote Desktop Protocol Remote Code Execution Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59787,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56194",
            "title": "Windows NFS Server Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.5779,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56647",
            "title": "Windows Remote Access Service Infrastructure Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.57789,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56648",
            "title": "Windows NFS Server Elevation of Privilege Vulnerability",
            "summary": "Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00509,
            "epssPercentile": 0.41581,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56649",
            "title": "Windows Network File System Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File System allows an unauthorized attacker to execute code over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00699,
            "epssPercentile": 0.50808,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56650",
            "title": "Windows Network File System Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57083",
            "title": "Windows Media Photo Codec Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.4355,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57084",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.43549,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57085",
            "title": "Windows Print Spooler Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0037,
            "epssPercentile": 0.30143,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57089",
            "title": "Windows SMB Server Network Transport Driver (srvnet.sys) Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00665,
            "epssPercentile": 0.49498,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57092",
            "title": "Microsoft Windows VMSwitch Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.",
            "score": 9.9,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.57791,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57093",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20053,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57095",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00489,
            "epssPercentile": 0.40353,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57096",
            "title": "Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57097",
            "title": "Microsoft XML Security Feature Bypass Vulnerability",
            "summary": "Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack.",
            "score": 6.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00503,
            "epssPercentile": 0.41172,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57976",
            "title": "Windows Active Directory Domain Services Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01138,
            "epssPercentile": 0.64468,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57979",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58034,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57982",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00995,
            "epssPercentile": 0.60375,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58531",
            "title": "Windows SMB Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00509,
            "epssPercentile": 0.41581,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58532",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.261,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58533",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58033,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58535",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58539",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58033,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58540",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58545",
            "title": "Windows Kernel Security Feature Bypass Vulnerability",
            "summary": "Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0035,
            "epssPercentile": 0.27951,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58546",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58033,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58594",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.5486,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58608",
            "title": "Windows Print Spooler Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00569,
            "epssPercentile": 0.45031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58609",
            "title": "Windows Graphics Component Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38794,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58614",
            "title": "Windows Kernel Security Feature Bypass Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33743,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58627",
            "title": "Windows DHCP Server Denial of Service Vulnerability",
            "summary": "Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58629",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.1808,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58637",
            "title": "Windows Client-Side Caching Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18082,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58638",
            "title": "Windows Boot Loader Security Feature Bypass Vulnerability",
            "summary": "Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.",
            "score": 6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00235,
            "epssPercentile": 0.14327,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58640",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29001,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Exploitation reported by the vendor source",
        "max_cvss": 9.9,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-57092",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-esu-kb5099445",
      "slug": "microsoft-2026-07-esu-kb5099445",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5099445",
      "title": "Deploy Microsoft ESU security update KB5099445",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5099445",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Windows Server 2012, Windows Server 2012 (Server Core installation)",
      "platform": "ESU",
      "release_version": "6.2.9200.26226",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 173 linked CVEs for Windows Server 2012, Windows Server 2012 (Server Core installation). Microsoft reports exploitation for CVE-2026-56155.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 173,
        "ids": [
          "CVE-2026-34346",
          "CVE-2026-40378",
          "CVE-2026-40400",
          "CVE-2026-42975",
          "CVE-2026-44806",
          "CVE-2026-49164",
          "CVE-2026-49177",
          "CVE-2026-49178",
          "CVE-2026-49180",
          "CVE-2026-49181",
          "CVE-2026-49184",
          "CVE-2026-49789",
          "CVE-2026-49790",
          "CVE-2026-49791",
          "CVE-2026-49794",
          "CVE-2026-49796",
          "CVE-2026-49797",
          "CVE-2026-49798",
          "CVE-2026-49799",
          "CVE-2026-49801",
          "CVE-2026-49803",
          "CVE-2026-49804",
          "CVE-2026-49805",
          "CVE-2026-50294",
          "CVE-2026-50297",
          "CVE-2026-50298",
          "CVE-2026-50304",
          "CVE-2026-50306",
          "CVE-2026-50308",
          "CVE-2026-50309",
          "CVE-2026-50311",
          "CVE-2026-50312",
          "CVE-2026-50313",
          "CVE-2026-50321",
          "CVE-2026-50325",
          "CVE-2026-50328",
          "CVE-2026-50330",
          "CVE-2026-50332",
          "CVE-2026-50334",
          "CVE-2026-50341",
          "CVE-2026-50344",
          "CVE-2026-50346",
          "CVE-2026-50347",
          "CVE-2026-50351",
          "CVE-2026-50352",
          "CVE-2026-50355",
          "CVE-2026-50359",
          "CVE-2026-50365",
          "CVE-2026-50366",
          "CVE-2026-50368",
          "CVE-2026-50369",
          "CVE-2026-50370",
          "CVE-2026-50371",
          "CVE-2026-50372",
          "CVE-2026-50376",
          "CVE-2026-50380",
          "CVE-2026-50386",
          "CVE-2026-50387",
          "CVE-2026-50388",
          "CVE-2026-50390",
          "CVE-2026-50391",
          "CVE-2026-50397",
          "CVE-2026-50400",
          "CVE-2026-50402",
          "CVE-2026-50405",
          "CVE-2026-50411",
          "CVE-2026-50412",
          "CVE-2026-50417",
          "CVE-2026-50419",
          "CVE-2026-50422",
          "CVE-2026-50426",
          "CVE-2026-50431",
          "CVE-2026-50433",
          "CVE-2026-50439",
          "CVE-2026-50444",
          "CVE-2026-50445",
          "CVE-2026-50447",
          "CVE-2026-50448",
          "CVE-2026-50451",
          "CVE-2026-50453",
          "CVE-2026-50455",
          "CVE-2026-50456",
          "CVE-2026-50461",
          "CVE-2026-50462",
          "CVE-2026-50470",
          "CVE-2026-50471",
          "CVE-2026-50474",
          "CVE-2026-50475",
          "CVE-2026-50476",
          "CVE-2026-50477",
          "CVE-2026-50480",
          "CVE-2026-50482",
          "CVE-2026-50485",
          "CVE-2026-50489",
          "CVE-2026-50490",
          "CVE-2026-50491",
          "CVE-2026-50494",
          "CVE-2026-50496",
          "CVE-2026-50497",
          "CVE-2026-50498",
          "CVE-2026-50500",
          "CVE-2026-50502",
          "CVE-2026-50504",
          "CVE-2026-50505",
          "CVE-2026-50518",
          "CVE-2026-50647",
          "CVE-2026-50667",
          "CVE-2026-50669",
          "CVE-2026-50673",
          "CVE-2026-50683",
          "CVE-2026-50684",
          "CVE-2026-50685",
          "CVE-2026-50688",
          "CVE-2026-50690",
          "CVE-2026-50694",
          "CVE-2026-50695",
          "CVE-2026-50697",
          "CVE-2026-54107",
          "CVE-2026-54115",
          "CVE-2026-54119",
          "CVE-2026-54121",
          "CVE-2026-54122",
          "CVE-2026-54126",
          "CVE-2026-54128",
          "CVE-2026-54982",
          "CVE-2026-54983",
          "CVE-2026-54989",
          "CVE-2026-54992",
          "CVE-2026-54995",
          "CVE-2026-54997",
          "CVE-2026-54999",
          "CVE-2026-55003",
          "CVE-2026-55004",
          "CVE-2026-56155",
          "CVE-2026-56159",
          "CVE-2026-56175",
          "CVE-2026-56176",
          "CVE-2026-56182",
          "CVE-2026-56186",
          "CVE-2026-56188",
          "CVE-2026-56189",
          "CVE-2026-56190",
          "CVE-2026-56194",
          "CVE-2026-56648",
          "CVE-2026-56649",
          "CVE-2026-56650",
          "CVE-2026-57083",
          "CVE-2026-57084",
          "CVE-2026-57085",
          "CVE-2026-57089",
          "CVE-2026-57092",
          "CVE-2026-57093",
          "CVE-2026-57095",
          "CVE-2026-57097",
          "CVE-2026-57976",
          "CVE-2026-57982",
          "CVE-2026-58531",
          "CVE-2026-58532",
          "CVE-2026-58533",
          "CVE-2026-58535",
          "CVE-2026-58539",
          "CVE-2026-58540",
          "CVE-2026-58545",
          "CVE-2026-58546",
          "CVE-2026-58594",
          "CVE-2026-58608",
          "CVE-2026-58609",
          "CVE-2026-58614",
          "CVE-2026-58627",
          "CVE-2026-58629",
          "CVE-2026-58637",
          "CVE-2026-58638",
          "CVE-2026-58640"
        ],
        "details": [
          {
            "id": "CVE-2026-34346",
            "title": "Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability",
            "summary": "Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0027,
            "epssPercentile": 0.18916,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-40378",
            "title": "Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability",
            "summary": "Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65473,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-40400",
            "title": "Windows PowerShell Remote Code Execution Vulnerability",
            "summary": "Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00868,
            "epssPercentile": 0.56393,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-42975",
            "title": "Windows Bluetooth Port Driver Remote Code Execution",
            "summary": "Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00536,
            "epssPercentile": 0.43257,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-44806",
            "title": "Windows Secure Channel Denial of Service Vulnerability",
            "summary": "Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65471,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49164",
            "title": "Windows Active Directory Domain Services Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53952,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49177",
            "title": "Windows TCP/IP Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00443,
            "epssPercentile": 0.37172,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49178",
            "title": "Windows Active Directory Domain Services Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.57789,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49180",
            "title": "Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00444,
            "epssPercentile": 0.37219,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49181",
            "title": "Windows DHCP Client Elevation of Privilege Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01172,
            "epssPercentile": 0.65406,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49184",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00337,
            "epssPercentile": 0.26479,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49789",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29002,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49790",
            "title": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
            "summary": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29001,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49791",
            "title": "Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0038,
            "epssPercentile": 0.31138,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49794",
            "title": "Windows USB Audio Class Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00468,
            "epssPercentile": 0.3893,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49796",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49797",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38802,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49798",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.",
            "score": 9.3,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00364,
            "epssPercentile": 0.29518,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49799",
            "title": "Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability",
            "summary": "Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01138,
            "epssPercentile": 0.64468,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49801",
            "title": "Windows SMB Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33744,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49803",
            "title": "Windows AppX Deployment Extensions Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.1017,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49804",
            "title": "Windows USB Video Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows USB Video Driver allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00483,
            "epssPercentile": 0.39895,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49805",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00236,
            "epssPercentile": 0.14488,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50294",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized attacker to disclose information locally.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00506,
            "epssPercentile": 0.41392,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50297",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00236,
            "epssPercentile": 0.14488,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50298",
            "title": "Windows Spaceport.sys Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36765,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50304",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50306",
            "title": "Windows TCP/IP Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26104,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50308",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38802,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50309",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26104,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50311",
            "title": "Windows Server Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50312",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 4.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0035,
            "epssPercentile": 0.28037,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50313",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38794,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50321",
            "title": "Windows USB Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11649,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50325",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00236,
            "epssPercentile": 0.14488,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50328",
            "title": "Windows Server Update Service (WSUS) Tampering Vulnerability",
            "summary": "Uncaught exception in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01232,
            "epssPercentile": 0.67,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50330",
            "title": "Windows Remote Desktop Client Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01252,
            "epssPercentile": 0.6748,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50332",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50334",
            "title": "Windows Push Notification Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Notification allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39645,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50341",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33741,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50344",
            "title": "Windows OLE Elevation of Privilege Vulnerability",
            "summary": "Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50346",
            "title": "Netlogon RPC Elevation of Privilege Vulnerability",
            "summary": "Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50347",
            "title": "Windows Data.dll Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38792,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50351",
            "title": "Windows Audio Compression Manager (ACM) Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50352",
            "title": "Windows Cryptographic Services Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50355",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50359",
            "title": "Microsoft XML Core Services Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20051,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50365",
            "title": "Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability",
            "summary": "Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00542,
            "epssPercentile": 0.43604,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50366",
            "title": "Windows Active Directory Domain Services Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01138,
            "epssPercentile": 0.64468,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50368",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50369",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00701,
            "epssPercentile": 0.50891,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50370",
            "title": "DHCP Server Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00502,
            "epssPercentile": 0.41141,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50371",
            "title": "Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows LUAFV allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10167,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50372",
            "title": "Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability",
            "summary": "Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18081,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50376",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50380",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.",
            "score": 9.6,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.54859,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50386",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38791,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50387",
            "title": "Windows GDI Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26111,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50388",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38797,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50390",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20053,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50391",
            "title": "Windows Group Policy Elevation of Privilege Vulnerability",
            "summary": "Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.2211,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50397",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18081,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50400",
            "title": "Windows App Package Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.2611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50402",
            "title": "NTFS Elevation of Privilege Vulnerability",
            "summary": "Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.2611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50405",
            "title": "Windows Filtering Platform Elevation of Privilege Vulnerability",
            "summary": "Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50411",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50412",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50417",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26111,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50419",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.",
            "score": 3.3,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00458,
            "epssPercentile": 0.38211,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50422",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50426",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent network.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00558,
            "epssPercentile": 0.44441,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50431",
            "title": "Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability",
            "summary": "Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39648,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50433",
            "title": "Windows Media Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Media allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50439",
            "title": "Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53953,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50444",
            "title": "Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00778,
            "epssPercentile": 0.53532,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50445",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58032,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50447",
            "title": "Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59787,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50448",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38799,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50451",
            "title": "Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00307,
            "epssPercentile": 0.23134,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50453",
            "title": "Windows USB Audio Class Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0051,
            "epssPercentile": 0.41673,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50455",
            "title": "Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33743,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50456",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39646,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50461",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38801,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50462",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00457,
            "epssPercentile": 0.38194,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50470",
            "title": "Windows Network Policy Server SNMP Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01027,
            "epssPercentile": 0.61358,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50471",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38793,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50474",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.54859,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50475",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.00375,
            "epssPercentile": 0.30678,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Medium technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50476",
            "title": "Windows Network Connections Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Windows allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20051,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50477",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.261,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50480",
            "title": "Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26097,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50482",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29001,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50485",
            "title": "Windows Hyper-V Denial of Service Vulnerability",
            "summary": "Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.",
            "score": 4.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00656,
            "epssPercentile": 0.49112,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50489",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50490",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20054,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50491",
            "title": "Code Integrity DLL (ci.dll) Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20054,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50494",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26098,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50496",
            "title": "Windows Network Policy Server SNMP Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50497",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58032,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50498",
            "title": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
            "summary": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00363,
            "epssPercentile": 0.29377,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50500",
            "title": "Windows Netlogon Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00742,
            "epssPercentile": 0.52348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50502",
            "title": "Windows Event Logging Service Remote Code Execution Vulnerability",
            "summary": "Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00654,
            "epssPercentile": 0.49042,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50504",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.5803,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50505",
            "title": "Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00742,
            "epssPercentile": 0.52348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50518",
            "title": "Windows DHCP Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59786,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50647",
            "title": "Active Directory Federation Server Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50667",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11651,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50669",
            "title": "Windows Telephony Server Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.1017,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50673",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.1165,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50683",
            "title": "Windows DHCP Client Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00576,
            "epssPercentile": 0.45358,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50684",
            "title": "Active Directory Federation Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Active Directory Federation Services (AD FS) allows an authorized attacker to perform spoofing over a network.",
            "score": 4.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00395,
            "epssPercentile": 0.32825,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50685",
            "title": "Windows DHCP Server Remote Code Execution Vulnerability",
            "summary": "Double free in Windows DHCP Server allows an authorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00663,
            "epssPercentile": 0.49414,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50688",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20053,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50690",
            "title": "Windows SMB Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50694",
            "title": "Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53953,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50695",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65468,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50697",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00395,
            "epssPercentile": 0.32743,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54107",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11651,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54115",
            "title": "Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26115,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54119",
            "title": "Windows Active Directory Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54121",
            "title": "Active Directory Certificate Services Elevation of Privilege Vulnerability",
            "summary": "Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01788,
            "epssPercentile": 0.76867,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54122",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00364,
            "epssPercentile": 0.29518,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54126",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58034,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54128",
            "title": "Windows DHCP Client Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00364,
            "epssPercentile": 0.29519,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54982",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00535,
            "epssPercentile": 0.43236,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54983",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65471,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54989",
            "title": "Quality Windows Audio/Video Experience (QWAVE) Elevation of Privilege Vulnerability",
            "summary": "Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20052,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54992",
            "title": "Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00337,
            "epssPercentile": 0.26479,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54995",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53953,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54997",
            "title": "Windows SMB Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54999",
            "title": "Windows TCP/IP Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0041,
            "epssPercentile": 0.34281,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55003",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55004",
            "title": "Windows Print Configuration Elevation of Privilege Vulnerability",
            "summary": "Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56155",
            "title": "Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability",
            "summary": "Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2026-07-14.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00346,
            "epssPercentile": 0.27582,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2026-07-28 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56159",
            "title": "DHCP Server Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59787,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56175",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26112,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56176",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26112,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56182",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26112,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56186",
            "title": "Windows Secure Channel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01106,
            "epssPercentile": 0.63644,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56188",
            "title": "Windows Server Network driver Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00607,
            "epssPercentile": 0.46852,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56189",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00393,
            "epssPercentile": 0.32499,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56190",
            "title": "Remote Desktop Protocol Remote Code Execution Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59787,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56194",
            "title": "Windows NFS Server Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.5779,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56648",
            "title": "Windows NFS Server Elevation of Privilege Vulnerability",
            "summary": "Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00509,
            "epssPercentile": 0.41581,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56649",
            "title": "Windows Network File System Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File System allows an unauthorized attacker to execute code over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00699,
            "epssPercentile": 0.50808,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56650",
            "title": "Windows Network File System Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57083",
            "title": "Windows Media Photo Codec Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.4355,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57084",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.43549,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57085",
            "title": "Windows Print Spooler Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0037,
            "epssPercentile": 0.30143,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57089",
            "title": "Windows SMB Server Network Transport Driver (srvnet.sys) Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00665,
            "epssPercentile": 0.49498,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57092",
            "title": "Microsoft Windows VMSwitch Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.",
            "score": 9.9,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.57791,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57093",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20053,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57095",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00489,
            "epssPercentile": 0.40353,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57097",
            "title": "Microsoft XML Security Feature Bypass Vulnerability",
            "summary": "Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack.",
            "score": 6.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00503,
            "epssPercentile": 0.41172,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57976",
            "title": "Windows Active Directory Domain Services Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01138,
            "epssPercentile": 0.64468,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57982",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00995,
            "epssPercentile": 0.60375,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58531",
            "title": "Windows SMB Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00509,
            "epssPercentile": 0.41581,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58532",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.261,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58533",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58033,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58535",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58539",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58033,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58540",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58545",
            "title": "Windows Kernel Security Feature Bypass Vulnerability",
            "summary": "Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0035,
            "epssPercentile": 0.27951,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58546",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58033,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58594",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.5486,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58608",
            "title": "Windows Print Spooler Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00569,
            "epssPercentile": 0.45031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58609",
            "title": "Windows Graphics Component Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38794,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58614",
            "title": "Windows Kernel Security Feature Bypass Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33743,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58627",
            "title": "Windows DHCP Server Denial of Service Vulnerability",
            "summary": "Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58629",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.1808,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58637",
            "title": "Windows Client-Side Caching Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18082,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58638",
            "title": "Windows Boot Loader Security Feature Bypass Vulnerability",
            "summary": "Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.",
            "score": 6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00235,
            "epssPercentile": 0.14327,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58640",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29001,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Exploitation reported by the vendor source",
        "max_cvss": 9.9,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-57092",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-esu-kb5099539",
      "slug": "microsoft-2026-07-esu-kb5099539",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5099539",
      "title": "Deploy Microsoft ESU security update KB5099539",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5099539",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Windows 10 Version 22H2 for 32-bit Systems, Windows 10 Version 22H2 for ARM64-based Systems, Windows 10 Version 22H2 for x64-based Systems",
      "platform": "ESU",
      "release_version": "10.0.19044.7548, 10.0.19045.7548",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 312 linked CVEs for Windows 10 Version 22H2 for 32-bit Systems, Windows 10 Version 22H2 for ARM64-based Systems, Windows 10 Version 22H2 for x64-based Systems. Microsoft marks CVE-2026-50661 as publicly disclosed, without that disclosure alone changing the BlackTree action window.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 312,
        "ids": [
          "CVE-2026-33842",
          "CVE-2026-34328",
          "CVE-2026-34346",
          "CVE-2026-34348",
          "CVE-2026-34349",
          "CVE-2026-40378",
          "CVE-2026-40400",
          "CVE-2026-40422",
          "CVE-2026-41087",
          "CVE-2026-42900",
          "CVE-2026-42975",
          "CVE-2026-42982",
          "CVE-2026-42990",
          "CVE-2026-44806",
          "CVE-2026-49164",
          "CVE-2026-49165",
          "CVE-2026-49167",
          "CVE-2026-49168",
          "CVE-2026-49170",
          "CVE-2026-49171",
          "CVE-2026-49172",
          "CVE-2026-49174",
          "CVE-2026-49175",
          "CVE-2026-49176",
          "CVE-2026-49177",
          "CVE-2026-49178",
          "CVE-2026-49180",
          "CVE-2026-49183",
          "CVE-2026-49184",
          "CVE-2026-49783",
          "CVE-2026-49784",
          "CVE-2026-49787",
          "CVE-2026-49788",
          "CVE-2026-49789",
          "CVE-2026-49790",
          "CVE-2026-49791",
          "CVE-2026-49792",
          "CVE-2026-49793",
          "CVE-2026-49794",
          "CVE-2026-49795",
          "CVE-2026-49796",
          "CVE-2026-49797",
          "CVE-2026-49798",
          "CVE-2026-49799",
          "CVE-2026-49800",
          "CVE-2026-49801",
          "CVE-2026-49803",
          "CVE-2026-49804",
          "CVE-2026-49805",
          "CVE-2026-49807",
          "CVE-2026-50293",
          "CVE-2026-50294",
          "CVE-2026-50296",
          "CVE-2026-50297",
          "CVE-2026-50298",
          "CVE-2026-50299",
          "CVE-2026-50300",
          "CVE-2026-50302",
          "CVE-2026-50303",
          "CVE-2026-50306",
          "CVE-2026-50307",
          "CVE-2026-50308",
          "CVE-2026-50309",
          "CVE-2026-50310",
          "CVE-2026-50311",
          "CVE-2026-50312",
          "CVE-2026-50313",
          "CVE-2026-50316",
          "CVE-2026-50318",
          "CVE-2026-50321",
          "CVE-2026-50325",
          "CVE-2026-50326",
          "CVE-2026-50329",
          "CVE-2026-50330",
          "CVE-2026-50331",
          "CVE-2026-50332",
          "CVE-2026-50333",
          "CVE-2026-50334",
          "CVE-2026-50335",
          "CVE-2026-50337",
          "CVE-2026-50339",
          "CVE-2026-50341",
          "CVE-2026-50343",
          "CVE-2026-50344",
          "CVE-2026-50346",
          "CVE-2026-50347",
          "CVE-2026-50348",
          "CVE-2026-50350",
          "CVE-2026-50351",
          "CVE-2026-50352",
          "CVE-2026-50354",
          "CVE-2026-50356",
          "CVE-2026-50357",
          "CVE-2026-50358",
          "CVE-2026-50359",
          "CVE-2026-50360",
          "CVE-2026-50362",
          "CVE-2026-50363",
          "CVE-2026-50364",
          "CVE-2026-50365",
          "CVE-2026-50366",
          "CVE-2026-50367",
          "CVE-2026-50369",
          "CVE-2026-50371",
          "CVE-2026-50372",
          "CVE-2026-50373",
          "CVE-2026-50374",
          "CVE-2026-50375",
          "CVE-2026-50376",
          "CVE-2026-50377",
          "CVE-2026-50378",
          "CVE-2026-50380",
          "CVE-2026-50381",
          "CVE-2026-50382",
          "CVE-2026-50383",
          "CVE-2026-50384",
          "CVE-2026-50386",
          "CVE-2026-50387",
          "CVE-2026-50388",
          "CVE-2026-50389",
          "CVE-2026-50390",
          "CVE-2026-50391",
          "CVE-2026-50394",
          "CVE-2026-50397",
          "CVE-2026-50399",
          "CVE-2026-50400",
          "CVE-2026-50401",
          "CVE-2026-50402",
          "CVE-2026-50405",
          "CVE-2026-50406",
          "CVE-2026-50407",
          "CVE-2026-50409",
          "CVE-2026-50410",
          "CVE-2026-50411",
          "CVE-2026-50412",
          "CVE-2026-50415",
          "CVE-2026-50417",
          "CVE-2026-50419",
          "CVE-2026-50421",
          "CVE-2026-50422",
          "CVE-2026-50423",
          "CVE-2026-50425",
          "CVE-2026-50427",
          "CVE-2026-50429",
          "CVE-2026-50430",
          "CVE-2026-50431",
          "CVE-2026-50432",
          "CVE-2026-50433",
          "CVE-2026-50434",
          "CVE-2026-50435",
          "CVE-2026-50437",
          "CVE-2026-50439",
          "CVE-2026-50441",
          "CVE-2026-50442",
          "CVE-2026-50445",
          "CVE-2026-50447",
          "CVE-2026-50448",
          "CVE-2026-50449",
          "CVE-2026-50450",
          "CVE-2026-50451",
          "CVE-2026-50452",
          "CVE-2026-50453",
          "CVE-2026-50455",
          "CVE-2026-50456",
          "CVE-2026-50457",
          "CVE-2026-50459",
          "CVE-2026-50460",
          "CVE-2026-50461",
          "CVE-2026-50462",
          "CVE-2026-50463",
          "CVE-2026-50469",
          "CVE-2026-50470",
          "CVE-2026-50471",
          "CVE-2026-50473",
          "CVE-2026-50474",
          "CVE-2026-50475",
          "CVE-2026-50476",
          "CVE-2026-50477",
          "CVE-2026-50478",
          "CVE-2026-50479",
          "CVE-2026-50482",
          "CVE-2026-50484",
          "CVE-2026-50485",
          "CVE-2026-50486",
          "CVE-2026-50489",
          "CVE-2026-50490",
          "CVE-2026-50491",
          "CVE-2026-50492",
          "CVE-2026-50493",
          "CVE-2026-50494",
          "CVE-2026-50495",
          "CVE-2026-50496",
          "CVE-2026-50497",
          "CVE-2026-50498",
          "CVE-2026-50499",
          "CVE-2026-50500",
          "CVE-2026-50502",
          "CVE-2026-50504",
          "CVE-2026-50505",
          "CVE-2026-50509",
          "CVE-2026-50647",
          "CVE-2026-50655",
          "CVE-2026-50661",
          "CVE-2026-50666",
          "CVE-2026-50667",
          "CVE-2026-50668",
          "CVE-2026-50669",
          "CVE-2026-50670",
          "CVE-2026-50672",
          "CVE-2026-50673",
          "CVE-2026-50680",
          "CVE-2026-50681",
          "CVE-2026-50682",
          "CVE-2026-50686",
          "CVE-2026-50688",
          "CVE-2026-50689",
          "CVE-2026-50690",
          "CVE-2026-50692",
          "CVE-2026-50694",
          "CVE-2026-50695",
          "CVE-2026-50696",
          "CVE-2026-50697",
          "CVE-2026-54107",
          "CVE-2026-54109",
          "CVE-2026-54112",
          "CVE-2026-54114",
          "CVE-2026-54115",
          "CVE-2026-54119",
          "CVE-2026-54122",
          "CVE-2026-54124",
          "CVE-2026-54125",
          "CVE-2026-54126",
          "CVE-2026-54128",
          "CVE-2026-54129",
          "CVE-2026-54132",
          "CVE-2026-54982",
          "CVE-2026-54983",
          "CVE-2026-54986",
          "CVE-2026-54987",
          "CVE-2026-54989",
          "CVE-2026-54992",
          "CVE-2026-54993",
          "CVE-2026-54995",
          "CVE-2026-54997",
          "CVE-2026-54999",
          "CVE-2026-55003",
          "CVE-2026-55004",
          "CVE-2026-56168",
          "CVE-2026-56173",
          "CVE-2026-56175",
          "CVE-2026-56176",
          "CVE-2026-56182",
          "CVE-2026-56184",
          "CVE-2026-56186",
          "CVE-2026-56188",
          "CVE-2026-56189",
          "CVE-2026-56190",
          "CVE-2026-56194",
          "CVE-2026-56643",
          "CVE-2026-56644",
          "CVE-2026-56647",
          "CVE-2026-56648",
          "CVE-2026-56649",
          "CVE-2026-56650",
          "CVE-2026-57083",
          "CVE-2026-57084",
          "CVE-2026-57085",
          "CVE-2026-57087",
          "CVE-2026-57089",
          "CVE-2026-57090",
          "CVE-2026-57091",
          "CVE-2026-57092",
          "CVE-2026-57093",
          "CVE-2026-57094",
          "CVE-2026-57095",
          "CVE-2026-57096",
          "CVE-2026-57097",
          "CVE-2026-57976",
          "CVE-2026-57979",
          "CVE-2026-57982",
          "CVE-2026-58526",
          "CVE-2026-58528",
          "CVE-2026-58530",
          "CVE-2026-58531",
          "CVE-2026-58532",
          "CVE-2026-58533",
          "CVE-2026-58534",
          "CVE-2026-58535",
          "CVE-2026-58536",
          "CVE-2026-58538",
          "CVE-2026-58539",
          "CVE-2026-58540",
          "CVE-2026-58541",
          "CVE-2026-58545",
          "CVE-2026-58546",
          "CVE-2026-58547",
          "CVE-2026-58594",
          "CVE-2026-58601",
          "CVE-2026-58608",
          "CVE-2026-58609",
          "CVE-2026-58610",
          "CVE-2026-58613",
          "CVE-2026-58614",
          "CVE-2026-58619",
          "CVE-2026-58626",
          "CVE-2026-58628",
          "CVE-2026-58629",
          "CVE-2026-58632",
          "CVE-2026-58635",
          "CVE-2026-58637",
          "CVE-2026-58638",
          "CVE-2026-58640"
        ],
        "details": [
          {
            "id": "CVE-2026-33842",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39646,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-34328",
            "title": "Windows Audio Service Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39644,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-34346",
            "title": "Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability",
            "summary": "Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0027,
            "epssPercentile": 0.18916,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-34348",
            "title": "Windows Event Logging Service Information Disclosure Vulnerability",
            "summary": "Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00907,
            "epssPercentile": 0.57588,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-34349",
            "title": "Windows Media Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39645,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-40378",
            "title": "Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability",
            "summary": "Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65473,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-40400",
            "title": "Windows PowerShell Remote Code Execution Vulnerability",
            "summary": "Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00868,
            "epssPercentile": 0.56393,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-40422",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33743,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-41087",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39643,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-42900",
            "title": "Microsoft Windows App Store Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00542,
            "epssPercentile": 0.43631,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-42975",
            "title": "Windows Bluetooth Port Driver Remote Code Execution",
            "summary": "Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00536,
            "epssPercentile": 0.43257,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-42982",
            "title": "Windows Secure Kernel Mode Elevation of Privilege Vulnerability",
            "summary": "Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26114,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-42990",
            "title": "SQL Server ODBC driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59786,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-44806",
            "title": "Windows Secure Channel Denial of Service Vulnerability",
            "summary": "Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65471,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49164",
            "title": "Windows Active Directory Domain Services Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53952,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49165",
            "title": "Microsoft Windows App Store Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00338,
            "epssPercentile": 0.26611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49167",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 4.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0035,
            "epssPercentile": 0.28037,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49168",
            "title": "Storage Spaces Direct Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36763,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49170",
            "title": "Windows StateRepository API Server file Elevation of Privilege Vulnerability",
            "summary": "Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.2211,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49171",
            "title": "Windows Speech Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.003,
            "epssPercentile": 0.22345,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49172",
            "title": "Windows FTP Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59785,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49174",
            "title": "DNS Client Tampering Vulnerability",
            "summary": "Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0027,
            "epssPercentile": 0.18886,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49175",
            "title": "Windows DNS Client Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26114,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49176",
            "title": "Windows WalletService Elevation of Privilege Vulnerability",
            "summary": "Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00471,
            "epssPercentile": 0.39116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49177",
            "title": "Windows TCP/IP Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00443,
            "epssPercentile": 0.37172,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49178",
            "title": "Windows Active Directory Domain Services Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.57789,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49180",
            "title": "Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00444,
            "epssPercentile": 0.37219,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49183",
            "title": "Windows Clipboard Server Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10168,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49184",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00337,
            "epssPercentile": 0.26479,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49783",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26114,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49784",
            "title": "Microsoft Windows App Store Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10169,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49787",
            "title": "HTTP.sys Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65471,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49788",
            "title": "HTTP/2 Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49789",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29002,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49790",
            "title": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
            "summary": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29001,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49791",
            "title": "Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0038,
            "epssPercentile": 0.31138,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49792",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26115,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49793",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26113,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49794",
            "title": "Windows USB Audio Class Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00468,
            "epssPercentile": 0.3893,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49795",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26115,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49796",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49797",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38802,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49798",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.",
            "score": 9.3,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00364,
            "epssPercentile": 0.29518,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49799",
            "title": "Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability",
            "summary": "Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01138,
            "epssPercentile": 0.64468,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49800",
            "title": "Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26115,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49801",
            "title": "Windows SMB Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33744,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49803",
            "title": "Windows AppX Deployment Extensions Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.1017,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49804",
            "title": "Windows USB Video Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows USB Video Driver allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00483,
            "epssPercentile": 0.39895,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49805",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00236,
            "epssPercentile": 0.14488,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49807",
            "title": "Windows DirectX Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows DirectX allows an unauthorized attacker to disclose information locally.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00506,
            "epssPercentile": 0.41392,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50293",
            "title": "Windows Internal Task Bar Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Internal Task Bar allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50294",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized attacker to disclose information locally.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00506,
            "epssPercentile": 0.41392,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50296",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Graphics Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18079,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50297",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00236,
            "epssPercentile": 0.14488,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50298",
            "title": "Windows Spaceport.sys Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36765,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50299",
            "title": "Windows Storage Spaces Direct Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36764,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50300",
            "title": "Windows DWM Core Library Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50302",
            "title": "Windows Cryptographic Services Security Feature Bypass Vulnerability",
            "summary": "Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 4.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00334,
            "epssPercentile": 0.2625,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50303",
            "title": "Windows Key Guard Security Feature Bypass Vulnerability",
            "summary": "Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0027,
            "epssPercentile": 0.18916,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50306",
            "title": "Windows TCP/IP Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26104,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50307",
            "title": "Windows TCP/IP Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20052,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50308",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38802,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50309",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26104,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50310",
            "title": "Windows Human Interface Device Information Disclosure Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information locally.",
            "score": 4.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23556,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50311",
            "title": "Windows Server Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50312",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 4.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0035,
            "epssPercentile": 0.28037,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50313",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38794,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50316",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39648,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50318",
            "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26103,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50321",
            "title": "Windows USB Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11649,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50325",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00236,
            "epssPercentile": 0.14488,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50326",
            "title": "Windows Unified Consent System Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Unified Consent System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50329",
            "title": "Microsoft DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50330",
            "title": "Windows Remote Desktop Client Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01252,
            "epssPercentile": 0.6748,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50331",
            "title": "Windows Application Model Core API Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Application Model allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50332",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50333",
            "title": "Windows Spaceport.sys Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50334",
            "title": "Windows Push Notification Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Notification allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39645,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50335",
            "title": "Windows Operating Systems Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50337",
            "title": "Windows Notification Elevation of Privilege Vulnerability",
            "summary": "Incorrect type conversion or cast in Windows Notification allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26104,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50339",
            "title": "Windows Push Notification Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39645,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50341",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33741,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50343",
            "title": "Microsoft Install Service Elevation of Privilege Vulnerability",
            "summary": "Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50344",
            "title": "Windows OLE Elevation of Privilege Vulnerability",
            "summary": "Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50346",
            "title": "Netlogon RPC Elevation of Privilege Vulnerability",
            "summary": "Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50347",
            "title": "Windows Data.dll Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38792,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50348",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0036,
            "epssPercentile": 0.29103,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50350",
            "title": "Windows Trusted Runtime Interface Driver Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39646,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50351",
            "title": "Windows Audio Compression Manager (ACM) Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50352",
            "title": "Windows Cryptographic Services Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50354",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26129,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50356",
            "title": "Microsoft Windows App Store Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10168,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50357",
            "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50358",
            "title": "Windows Media Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Media allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20051,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50359",
            "title": "Microsoft XML Core Services Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20051,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50360",
            "title": "Windows SMB Server Elevation of Privilege Vulnerability",
            "summary": "Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00778,
            "epssPercentile": 0.53532,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50362",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38801,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50363",
            "title": "Windows Push Notifications Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26102,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50364",
            "title": "Windows Backup Service Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows Server Backup allows an authorized attacker to elevate privileges locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00469,
            "epssPercentile": 0.38948,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50365",
            "title": "Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability",
            "summary": "Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00542,
            "epssPercentile": 0.43604,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50366",
            "title": "Windows Active Directory Domain Services Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01138,
            "epssPercentile": 0.64468,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50367",
            "title": "Windows Sensor Data Service Elevation of Privilege Vulnerability",
            "summary": "Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26103,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50369",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00701,
            "epssPercentile": 0.50891,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50371",
            "title": "Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows LUAFV allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10167,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50372",
            "title": "Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability",
            "summary": "Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18081,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50373",
            "title": "Windows Search Service Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50374",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00347,
            "epssPercentile": 0.27656,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50375",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DirectX allows an authorized attacker to elevate privileges locally.",
            "score": 6.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00295,
            "epssPercentile": 0.21728,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50376",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50377",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00409,
            "epssPercentile": 0.34158,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50378",
            "title": "Windows Key Guard Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Key Guard allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11649,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50380",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.",
            "score": 9.6,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.54859,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50381",
            "title": "Composite Image File System driver (cimfs.sys) Information Disclosure Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Composite Image File System Driver allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33744,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50382",
            "title": "DirectX Graphics Kernel Remote Code Execution Vulnerability",
            "summary": "Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50383",
            "title": "Windows Print Spooler Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33741,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50384",
            "title": "Windows Clip Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clip Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10168,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50386",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38791,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50387",
            "title": "Windows GDI Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26111,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50388",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38797,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50389",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39644,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50390",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20053,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50391",
            "title": "Windows Group Policy Elevation of Privilege Vulnerability",
            "summary": "Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.2211,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50394",
            "title": "Windows Media Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39643,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50397",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18081,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50399",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26111,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50400",
            "title": "Windows App Package Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.2611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50401",
            "title": "Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33744,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50402",
            "title": "NTFS Elevation of Privilege Vulnerability",
            "summary": "Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.2611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50405",
            "title": "Windows Filtering Platform Elevation of Privilege Vulnerability",
            "summary": "Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50406",
            "title": "Windows Backup Engine Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Backup Engine allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20052,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50407",
            "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50409",
            "title": "Windows Overlay Filter Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Overlay Filter allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50410",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18079,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50411",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50412",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50415",
            "title": "Windows Media Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Media allows an unauthorized attacker to disclose information over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0086,
            "epssPercentile": 0.56162,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50417",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26111,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50419",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.",
            "score": 3.3,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00458,
            "epssPercentile": 0.38211,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50421",
            "title": "Windows Connected User Experiences and Telemetry Elevation of Privilege Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.2611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50422",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50423",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50425",
            "title": "Windows Internal System User Profile Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Internal System User Profile allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50427",
            "title": "Content Delivery Manager Elevation of Privilege Vulnerability",
            "summary": "Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17026,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50429",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network.",
            "score": 8.2,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01069,
            "epssPercentile": 0.62606,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50430",
            "title": "Windows Push Notification Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39648,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50431",
            "title": "Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability",
            "summary": "Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39648,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50432",
            "title": "Window Virtual Filtering Platform (VFP) Denial of Service Vulnerability",
            "summary": "Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized attacker to deny service over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00953,
            "epssPercentile": 0.59049,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50433",
            "title": "Windows Media Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Media allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50434",
            "title": "Windows Push Notification Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50435",
            "title": "Windows Overlay Filter Elevation of Privilege Vulnerability",
            "summary": "Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50437",
            "title": "Windows DWM Core Library Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50439",
            "title": "Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53953,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50441",
            "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
            "summary": "Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.2611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50442",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39646,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50445",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58032,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50447",
            "title": "Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59787,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50448",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38799,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50449",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18082,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50450",
            "title": "Windows Network Connections Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10166,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50451",
            "title": "Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00307,
            "epssPercentile": 0.23134,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50452",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0036,
            "epssPercentile": 0.29103,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50453",
            "title": "Windows USB Audio Class Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0051,
            "epssPercentile": 0.41673,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50455",
            "title": "Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33743,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50456",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39646,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50457",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17027,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50459",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22679,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50460",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00542,
            "epssPercentile": 0.4363,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50461",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38801,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50462",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00457,
            "epssPercentile": 0.38194,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50463",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01027,
            "epssPercentile": 0.61357,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50469",
            "title": "Windows Projected File System Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows Projected File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0037,
            "epssPercentile": 0.30149,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50470",
            "title": "Windows Network Policy Server SNMP Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01027,
            "epssPercentile": 0.61358,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50471",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38793,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50473",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39644,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50474",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.54859,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50475",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.00375,
            "epssPercentile": 0.30678,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Medium technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50476",
            "title": "Windows Network Connections Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Windows allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20051,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50477",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.261,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50478",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26097,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50479",
            "title": "Windows USB Hub Driver Elevation of Privilege Vulnerability",
            "summary": "Untrusted pointer dereference in Windows USB Hub Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26097,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50482",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29001,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50484",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26112,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50485",
            "title": "Windows Hyper-V Denial of Service Vulnerability",
            "summary": "Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.",
            "score": 4.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00656,
            "epssPercentile": 0.49112,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50486",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26097,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50489",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50490",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20054,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50491",
            "title": "Code Integrity DLL (ci.dll) Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20054,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50492",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36764,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50493",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26098,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50494",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26098,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50495",
            "title": "DNS Client Tampering Vulnerability",
            "summary": "Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00302,
            "epssPercentile": 0.22534,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50496",
            "title": "Windows Network Policy Server SNMP Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50497",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58032,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50498",
            "title": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
            "summary": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00363,
            "epssPercentile": 0.29377,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50499",
            "title": "Windows Print Spooler Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50500",
            "title": "Windows Netlogon Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00742,
            "epssPercentile": 0.52348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50502",
            "title": "Windows Event Logging Service Remote Code Execution Vulnerability",
            "summary": "Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00654,
            "epssPercentile": 0.49042,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50504",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.5803,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50505",
            "title": "Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00742,
            "epssPercentile": 0.52348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50509",
            "title": "Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability",
            "summary": "Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0353,
            "epssPercentile": 0.88474,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50647",
            "title": "Active Directory Federation Server Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50655",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38797,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50661",
            "title": "Windows BitLocker Security Feature Bypass Vulnerability",
            "summary": "Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00481,
            "epssPercentile": 0.39822,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50666",
            "title": "Windows Remote Access Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.5779,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50667",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11651,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50668",
            "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36764,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50669",
            "title": "Windows Telephony Server Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.1017,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50670",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26096,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50672",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10166,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50673",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.1165,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50680",
            "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally.",
            "score": 8.2,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00338,
            "epssPercentile": 0.26665,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50681",
            "title": "Windows Secure Channel Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39645,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50682",
            "title": "Active Directory Denial of Service Vulnerability",
            "summary": "Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58293,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50686",
            "title": "Windows OLE Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00707,
            "epssPercentile": 0.5113,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50688",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20053,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50689",
            "title": "Windows Clipboard Server Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17026,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50690",
            "title": "Windows SMB Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50692",
            "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.261,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50694",
            "title": "Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53953,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50695",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65468,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50696",
            "title": "Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50697",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00395,
            "epssPercentile": 0.32743,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54107",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11651,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54109",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54112",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10171,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54114",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54115",
            "title": "Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26115,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54119",
            "title": "Windows Active Directory Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54122",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00364,
            "epssPercentile": 0.29518,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54124",
            "title": "Windows Terminal Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.388,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54125",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17027,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54126",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58034,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54128",
            "title": "Windows DHCP Client Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00364,
            "epssPercentile": 0.29519,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54129",
            "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20054,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54132",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36764,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54982",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00535,
            "epssPercentile": 0.43236,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54983",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65471,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54986",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26113,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54987",
            "title": "Windows Overlay Filter Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54989",
            "title": "Quality Windows Audio/Video Experience (QWAVE) Elevation of Privilege Vulnerability",
            "summary": "Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20052,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54992",
            "title": "Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00337,
            "epssPercentile": 0.26479,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54993",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38795,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54995",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53953,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54997",
            "title": "Windows SMB Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54999",
            "title": "Windows TCP/IP Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0041,
            "epssPercentile": 0.34281,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55003",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55004",
            "title": "Windows Print Configuration Elevation of Privilege Vulnerability",
            "summary": "Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56168",
            "title": "Windows SMB Server Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01138,
            "epssPercentile": 0.64469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56173",
            "title": "Windows WebView Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18078,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56175",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26112,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56176",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26112,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56182",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26112,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56184",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39643,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56186",
            "title": "Windows Secure Channel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01106,
            "epssPercentile": 0.63644,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56188",
            "title": "Windows Server Network driver Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00607,
            "epssPercentile": 0.46852,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56189",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00393,
            "epssPercentile": 0.32499,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56190",
            "title": "Remote Desktop Protocol Remote Code Execution Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59787,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56194",
            "title": "Windows NFS Server Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.5779,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56643",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56644",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56647",
            "title": "Windows Remote Access Service Infrastructure Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.57789,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56648",
            "title": "Windows NFS Server Elevation of Privilege Vulnerability",
            "summary": "Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00509,
            "epssPercentile": 0.41581,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56649",
            "title": "Windows Network File System Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File System allows an unauthorized attacker to execute code over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00699,
            "epssPercentile": 0.50808,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56650",
            "title": "Windows Network File System Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57083",
            "title": "Windows Media Photo Codec Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.4355,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57084",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.43549,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57085",
            "title": "Windows Print Spooler Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0037,
            "epssPercentile": 0.30143,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57087",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53969,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57089",
            "title": "Windows SMB Server Network Transport Driver (srvnet.sys) Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00665,
            "epssPercentile": 0.49498,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57090",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.54858,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57091",
            "title": "Windows File History Service Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows File History Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57092",
            "title": "Microsoft Windows VMSwitch Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.",
            "score": 9.9,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.57791,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57093",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20053,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57094",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.54859,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57095",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00489,
            "epssPercentile": 0.40353,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57096",
            "title": "Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57097",
            "title": "Microsoft XML Security Feature Bypass Vulnerability",
            "summary": "Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack.",
            "score": 6.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00503,
            "epssPercentile": 0.41172,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57976",
            "title": "Windows Active Directory Domain Services Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01138,
            "epssPercentile": 0.64468,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57979",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58034,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57982",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00995,
            "epssPercentile": 0.60375,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58526",
            "title": "Windows Storage Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Storage allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11648,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58528",
            "title": "Windows USB Audio Class Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00524,
            "epssPercentile": 0.42584,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58530",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00363,
            "epssPercentile": 0.29377,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58531",
            "title": "Windows SMB Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00509,
            "epssPercentile": 0.41581,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58532",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.261,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58533",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58033,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58534",
            "title": "Windows Input Method Editor (IME) Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26095,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58535",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58536",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26095,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58538",
            "title": "Windows Bluetooth Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26101,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58539",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58033,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58540",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58541",
            "title": "Microsoft DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26102,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58545",
            "title": "Windows Kernel Security Feature Bypass Vulnerability",
            "summary": "Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0035,
            "epssPercentile": 0.27951,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58546",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58033,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58547",
            "title": "Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00407,
            "epssPercentile": 0.33974,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58594",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.5486,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58601",
            "title": "Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability",
            "summary": "Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26102,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58608",
            "title": "Windows Print Spooler Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00569,
            "epssPercentile": 0.45031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58609",
            "title": "Windows Graphics Component Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38794,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58610",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38797,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58613",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.00377,
            "epssPercentile": 0.30833,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58614",
            "title": "Windows Kernel Security Feature Bypass Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33743,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58619",
            "title": "Windows Sensor Data Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.1808,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58626",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.57789,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58628",
            "title": "Windows Wireless Network Manager Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10171,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58629",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.1808,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58632",
            "title": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26101,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58635",
            "title": "Windows Narrator Braille Elevation of Privilege Vulnerability",
            "summary": "Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00322,
            "epssPercentile": 0.24873,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58637",
            "title": "Windows Client-Side Caching Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18082,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58638",
            "title": "Windows Boot Loader Security Feature Bypass Vulnerability",
            "summary": "Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.",
            "score": 6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00235,
            "epssPercentile": 0.14327,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58640",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29001,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.9,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-57092",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-esu-kb5103213",
      "slug": "microsoft-2026-07-esu-kb5103213",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5103213",
      "title": "Deploy Microsoft ESU security update KB5103213",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5103213",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft Exchange Server 2019 Cumulative Update 15",
      "platform": "ESU",
      "release_version": "15.02.1748.048",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 4 linked CVEs for Microsoft Exchange Server 2019 Cumulative Update 15.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 4,
        "ids": [
          "CVE-2026-55005",
          "CVE-2026-55006",
          "CVE-2026-55008",
          "CVE-2026-55009"
        ],
        "details": [
          {
            "id": "CVE-2026-55005",
            "title": "Microsoft Exchange Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.57789,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55006",
            "title": "Microsoft Exchange Server Elevation of Privilege Vulnerability",
            "summary": "Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55008",
            "title": "Microsoft Exchange Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.",
            "score": 9.6,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00863,
            "epssPercentile": 0.56246,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55009",
            "title": "Microsoft Exchange Server Elevation of Privilege Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02513,
            "epssPercentile": 0.83741,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.6,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-55008",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-esu-kb5103214",
      "slug": "microsoft-2026-07-esu-kb5103214",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5103214",
      "title": "Deploy Microsoft ESU security update KB5103214",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5103214",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft Exchange Server 2019 Cumulative Update 14",
      "platform": "ESU",
      "release_version": "15.02.1544.043",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 4 linked CVEs for Microsoft Exchange Server 2019 Cumulative Update 14.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 4,
        "ids": [
          "CVE-2026-55005",
          "CVE-2026-55006",
          "CVE-2026-55008",
          "CVE-2026-55009"
        ],
        "details": [
          {
            "id": "CVE-2026-55005",
            "title": "Microsoft Exchange Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.57789,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55006",
            "title": "Microsoft Exchange Server Elevation of Privilege Vulnerability",
            "summary": "Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55008",
            "title": "Microsoft Exchange Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.",
            "score": 9.6,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00863,
            "epssPercentile": 0.56246,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55009",
            "title": "Microsoft Exchange Server Elevation of Privilege Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02513,
            "epssPercentile": 0.83741,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.6,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-55008",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-esu-kb5103215",
      "slug": "microsoft-2026-07-esu-kb5103215",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5103215",
      "title": "Deploy Microsoft ESU security update KB5103215",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5103215",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft Exchange Server 2016 Cumulative Update 23",
      "platform": "ESU",
      "release_version": "15.01.2507.071",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 4 linked CVEs for Microsoft Exchange Server 2016 Cumulative Update 23.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 4,
        "ids": [
          "CVE-2026-55005",
          "CVE-2026-55006",
          "CVE-2026-55008",
          "CVE-2026-55009"
        ],
        "details": [
          {
            "id": "CVE-2026-55005",
            "title": "Microsoft Exchange Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.57789,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55006",
            "title": "Microsoft Exchange Server Elevation of Privilege Vulnerability",
            "summary": "Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55008",
            "title": "Microsoft Exchange Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.",
            "score": 9.6,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00863,
            "epssPercentile": 0.56246,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55009",
            "title": "Microsoft Exchange Server Elevation of Privilege Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02513,
            "epssPercentile": 0.83741,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.6,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-55008",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-microsoft-dynamics-msrc-2026-07-microsoft-dynamics-release-notes-microsoft-dynamics-nav-2018",
      "slug": "microsoft-2026-07-microsoft-dynamics-msrc-2026-07-microsoft-dynamics-release-notes-microsoft-dynamics-nav-2018",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-07-microsoft-dynamics-release-notes",
      "title": "Deploy Microsoft Microsoft Dynamics update for Microsoft Dynamics NAV 2018",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://www.microsoft.com/en-us/download/details.aspx?id=108720",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft Dynamics NAV 2018",
      "platform": "Microsoft Dynamics",
      "release_version": "11.0.50704.0",
      "action_type": "deploy-patch",
      "restart_required": "no",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Dynamics NAV 2018.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-55944"
        ],
        "details": [
          {
            "id": "CVE-2026-55944",
            "title": "Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01532,
            "epssPercentile": 0.7311,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-55944",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "The reviewed source does not require a restart.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-microsoft-office-kb5002273",
      "slug": "microsoft-2026-07-microsoft-office-kb5002273",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002273",
      "title": "Deploy Microsoft Microsoft Office security update KB5002273",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002273",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition)",
      "platform": "Microsoft Office",
      "release_version": "16.0.5561.1000",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 2,
        "ids": [
          "CVE-2026-47290",
          "CVE-2026-55017"
        ],
        "details": [
          {
            "id": "CVE-2026-47290",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38798,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55017",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.3879,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-55017",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-microsoft-office-kb5002748",
      "slug": "microsoft-2026-07-microsoft-office-kb5002748",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002748",
      "title": "Deploy Microsoft Microsoft Office security update KB5002748",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002748",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition)",
      "platform": "Microsoft Office",
      "release_version": "16.0.5561.1000",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 2,
        "ids": [
          "CVE-2026-55049",
          "CVE-2026-55140"
        ],
        "details": [
          {
            "id": "CVE-2026-55049",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38803,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55140",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38793,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-55140",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-microsoft-office-kb5002830",
      "slug": "microsoft-2026-07-microsoft-office-kb5002830",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002830",
      "title": "Deploy Microsoft Microsoft Office security update KB5002830",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002830",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition)",
      "platform": "Microsoft Office",
      "release_version": "16.0.5561.1001",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-55140"
        ],
        "details": [
          {
            "id": "CVE-2026-55140",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38793,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-55140",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-microsoft-office-kb5002867",
      "slug": "microsoft-2026-07-microsoft-office-kb5002867",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002867",
      "title": "Deploy Microsoft Microsoft Office security update KB5002867",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002867",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft PowerPoint 2016 (32-bit edition), Microsoft PowerPoint 2016 (64-bit edition)",
      "platform": "Microsoft Office",
      "release_version": "16.0.5561.1000",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft PowerPoint 2016 (32-bit edition), Microsoft PowerPoint 2016 (64-bit edition).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 3,
        "ids": [
          "CVE-2026-55043",
          "CVE-2026-55120",
          "CVE-2026-55123"
        ],
        "details": [
          {
            "id": "CVE-2026-55043",
            "title": "Microsoft PowerPoint Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55120",
            "title": "Microsoft PowerPoint Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38796,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55123",
            "title": "Microsoft PowerPoint Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38798,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-55123",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-microsoft-office-kb5002873",
      "slug": "microsoft-2026-07-microsoft-office-kb5002873",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002873",
      "title": "Deploy Microsoft Microsoft Office security update KB5002873",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002873",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft SharePoint Server Subscription Edition",
      "platform": "Microsoft Office",
      "release_version": "16.0.19725.20384",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft SharePoint Server Subscription Edition. Microsoft reports exploitation for CVE-2026-58644.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-58644"
        ],
        "details": [
          {
            "id": "CVE-2026-58644",
            "title": "Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
            "summary": "Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2026-07-16.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.15873,
            "epssPercentile": 0.9666,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2026-07-19 as the remediation due date.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Exploitation reported by the vendor source",
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-58644",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-microsoft-office-kb5002874",
      "slug": "microsoft-2026-07-microsoft-office-kb5002874",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002874",
      "title": "Deploy Microsoft Microsoft Office security update KB5002874",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002874",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft SharePoint Server 2019",
      "platform": "Microsoft Office",
      "release_version": "16.0.10417.20153",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft SharePoint Server 2019. Microsoft reports exploitation for CVE-2026-58644.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-58644"
        ],
        "details": [
          {
            "id": "CVE-2026-58644",
            "title": "Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
            "summary": "Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2026-07-16.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.15873,
            "epssPercentile": 0.9666,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2026-07-19 as the remediation due date.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Exploitation reported by the vendor source",
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-58644",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-microsoft-office-kb5002880",
      "slug": "microsoft-2026-07-microsoft-office-kb5002880",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002880",
      "title": "Deploy Microsoft Microsoft Office security update KB5002880",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002880",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "platform": "Microsoft Office",
      "release_version": "16.0.5556.1005",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft SharePoint Enterprise Server 2016. Microsoft reports exploitation for CVE-2026-58644.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-58644"
        ],
        "details": [
          {
            "id": "CVE-2026-58644",
            "title": "Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
            "summary": "Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2026-07-16.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.15873,
            "epssPercentile": 0.9666,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2026-07-19 as the remediation due date.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Exploitation reported by the vendor source",
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-58644",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-microsoft-office-kb5002882",
      "slug": "microsoft-2026-07-microsoft-office-kb5002882",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002882",
      "title": "Deploy Microsoft Microsoft Office security update KB5002882",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002882",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft SharePoint Server Subscription Edition",
      "platform": "Microsoft Office",
      "release_version": "16.0.19725.20434",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 37 linked CVEs for Microsoft SharePoint Server Subscription Edition. Microsoft reports exploitation for CVE-2026-56164.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 37,
        "ids": [
          "CVE-2026-50522",
          "CVE-2026-54108",
          "CVE-2026-55016",
          "CVE-2026-55019",
          "CVE-2026-55020",
          "CVE-2026-55021",
          "CVE-2026-55023",
          "CVE-2026-55026",
          "CVE-2026-55027",
          "CVE-2026-55028",
          "CVE-2026-55030",
          "CVE-2026-55032",
          "CVE-2026-55033",
          "CVE-2026-55034",
          "CVE-2026-55035",
          "CVE-2026-55038",
          "CVE-2026-55040",
          "CVE-2026-55045",
          "CVE-2026-55047",
          "CVE-2026-55050",
          "CVE-2026-55051",
          "CVE-2026-55052",
          "CVE-2026-55055",
          "CVE-2026-55121",
          "CVE-2026-55124",
          "CVE-2026-55125",
          "CVE-2026-55126",
          "CVE-2026-55127",
          "CVE-2026-55128",
          "CVE-2026-55130",
          "CVE-2026-55132",
          "CVE-2026-55134",
          "CVE-2026-55135",
          "CVE-2026-55142",
          "CVE-2026-56157",
          "CVE-2026-56164",
          "CVE-2026-56192"
        ],
        "details": [
          {
            "id": "CVE-2026-50522",
            "title": "Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
            "summary": "Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2026-07-22.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.84606,
            "epssPercentile": 0.99688,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2026-07-25 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54108",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01079,
            "epssPercentile": 0.62863,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55016",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00583,
            "epssPercentile": 0.45721,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55019",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00583,
            "epssPercentile": 0.45722,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55020",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00583,
            "epssPercentile": 0.45721,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55021",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00946,
            "epssPercentile": 0.58847,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55023",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46271,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55026",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00449,
            "epssPercentile": 0.37607,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55027",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46272,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55028",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46271,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55030",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00583,
            "epssPercentile": 0.45722,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55032",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45122,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55033",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45123,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55034",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00946,
            "epssPercentile": 0.58848,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55035",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00574,
            "epssPercentile": 0.45266,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55038",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45122,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55040",
            "title": "Microsoft SharePoint Weak Authentication Vulnerability",
            "summary": "Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 9.1,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2026-08-18.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.39652,
            "epssPercentile": 0.98521,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2026-08-21 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55045",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00446,
            "epssPercentile": 0.3738,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55047",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46272,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55050",
            "title": "Microsoft Word Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46271,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55051",
            "title": "Microsoft SharePoint Server Information Disclosure Vulnerability",
            "summary": "Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00911,
            "epssPercentile": 0.57717,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55052",
            "title": "Microsoft SharePoint Elevation of Privilege Vulnerability",
            "summary": "Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0094,
            "epssPercentile": 0.58631,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55055",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45123,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55121",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00513,
            "epssPercentile": 0.41842,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55124",
            "title": "Microsoft Word Information Disclosure Vulnerability",
            "summary": "Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46272,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55125",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45125,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55126",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00649,
            "epssPercentile": 0.48806,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55127",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45124,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55128",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45123,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55130",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45123,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55132",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45124,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55134",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45124,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55135",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00583,
            "epssPercentile": 0.45722,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55142",
            "title": "Microsoft Word Information Disclosure Vulnerability",
            "summary": "Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46273,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56157",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 5.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00496,
            "epssPercentile": 0.40764,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56164",
            "title": "Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability",
            "summary": "Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2026-07-14.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.26636,
            "epssPercentile": 0.97882,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2026-07-17 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56192",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46273,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Exploitation reported by the vendor source",
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-50522",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-microsoft-office-kb5002883",
      "slug": "microsoft-2026-07-microsoft-office-kb5002883",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002883",
      "title": "Deploy Microsoft Microsoft Office security update KB5002883",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002883",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft SharePoint Server 2019",
      "platform": "Microsoft Office",
      "release_version": "16.0.10417.20175",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 38 linked CVEs for Microsoft SharePoint Server 2019. Microsoft reports exploitation for CVE-2026-56164.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 38,
        "ids": [
          "CVE-2026-50522",
          "CVE-2026-54108",
          "CVE-2026-55016",
          "CVE-2026-55019",
          "CVE-2026-55020",
          "CVE-2026-55021",
          "CVE-2026-55023",
          "CVE-2026-55026",
          "CVE-2026-55027",
          "CVE-2026-55028",
          "CVE-2026-55030",
          "CVE-2026-55032",
          "CVE-2026-55033",
          "CVE-2026-55034",
          "CVE-2026-55035",
          "CVE-2026-55038",
          "CVE-2026-55040",
          "CVE-2026-55045",
          "CVE-2026-55047",
          "CVE-2026-55050",
          "CVE-2026-55051",
          "CVE-2026-55052",
          "CVE-2026-55055",
          "CVE-2026-55121",
          "CVE-2026-55124",
          "CVE-2026-55125",
          "CVE-2026-55126",
          "CVE-2026-55127",
          "CVE-2026-55128",
          "CVE-2026-55130",
          "CVE-2026-55132",
          "CVE-2026-55134",
          "CVE-2026-55135",
          "CVE-2026-55142",
          "CVE-2026-56157",
          "CVE-2026-56164",
          "CVE-2026-56192",
          "CVE-2026-58277"
        ],
        "details": [
          {
            "id": "CVE-2026-50522",
            "title": "Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
            "summary": "Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2026-07-22.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.84606,
            "epssPercentile": 0.99688,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2026-07-25 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54108",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01079,
            "epssPercentile": 0.62863,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55016",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00583,
            "epssPercentile": 0.45721,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55019",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00583,
            "epssPercentile": 0.45722,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55020",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00583,
            "epssPercentile": 0.45721,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55021",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00946,
            "epssPercentile": 0.58847,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55023",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46271,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55026",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00449,
            "epssPercentile": 0.37607,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55027",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46272,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55028",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46271,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55030",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00583,
            "epssPercentile": 0.45722,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55032",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45122,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55033",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45123,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55034",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00946,
            "epssPercentile": 0.58848,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55035",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00574,
            "epssPercentile": 0.45266,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55038",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45122,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55040",
            "title": "Microsoft SharePoint Weak Authentication Vulnerability",
            "summary": "Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 9.1,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2026-08-18.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.39652,
            "epssPercentile": 0.98521,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2026-08-21 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55045",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00446,
            "epssPercentile": 0.3738,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55047",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46272,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55050",
            "title": "Microsoft Word Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46271,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55051",
            "title": "Microsoft SharePoint Server Information Disclosure Vulnerability",
            "summary": "Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00911,
            "epssPercentile": 0.57717,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55052",
            "title": "Microsoft SharePoint Elevation of Privilege Vulnerability",
            "summary": "Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0094,
            "epssPercentile": 0.58631,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55055",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45123,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55121",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00513,
            "epssPercentile": 0.41842,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55124",
            "title": "Microsoft Word Information Disclosure Vulnerability",
            "summary": "Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46272,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55125",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45125,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55126",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00649,
            "epssPercentile": 0.48806,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55127",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45124,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55128",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45123,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55130",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45123,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55132",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45124,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55134",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45124,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55135",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00583,
            "epssPercentile": 0.45722,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55142",
            "title": "Microsoft Word Information Disclosure Vulnerability",
            "summary": "Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46273,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56157",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 5.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00496,
            "epssPercentile": 0.40764,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56164",
            "title": "Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability",
            "summary": "Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2026-07-14.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.26636,
            "epssPercentile": 0.97882,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2026-07-17 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56192",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46273,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58277",
            "title": "Microsoft SharePoint Elevation of Privilege Vulnerability",
            "summary": "Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0094,
            "epssPercentile": 0.58631,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Exploitation reported by the vendor source",
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-50522",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-microsoft-office-kb5002884",
      "slug": "microsoft-2026-07-microsoft-office-kb5002884",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002884",
      "title": "Deploy Microsoft Microsoft Office security update KB5002884",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002884",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Office Online Server",
      "platform": "Microsoft Office",
      "release_version": "16.0.10417.20175",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 33 linked CVEs for Office Online Server.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 33,
        "ids": [
          "CVE-2026-47642",
          "CVE-2026-48580",
          "CVE-2026-50408",
          "CVE-2026-50675",
          "CVE-2026-50678",
          "CVE-2026-54131",
          "CVE-2026-54988",
          "CVE-2026-55024",
          "CVE-2026-55025",
          "CVE-2026-55029",
          "CVE-2026-55031",
          "CVE-2026-55036",
          "CVE-2026-55037",
          "CVE-2026-55039",
          "CVE-2026-55041",
          "CVE-2026-55044",
          "CVE-2026-55046",
          "CVE-2026-55048",
          "CVE-2026-55053",
          "CVE-2026-55054",
          "CVE-2026-55058",
          "CVE-2026-55122",
          "CVE-2026-55131",
          "CVE-2026-55136",
          "CVE-2026-55137",
          "CVE-2026-55138",
          "CVE-2026-55141",
          "CVE-2026-55898",
          "CVE-2026-55899",
          "CVE-2026-55947",
          "CVE-2026-55948",
          "CVE-2026-55949",
          "CVE-2026-58618"
        ],
        "details": [
          {
            "id": "CVE-2026-47642",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38796,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48580",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.43549,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50408",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.4355,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50675",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38794,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50678",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00472,
            "epssPercentile": 0.39218,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54131",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38792,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54988",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00461,
            "epssPercentile": 0.38449,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55024",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38793,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55025",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38795,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55029",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38795,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55031",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38795,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55036",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38796,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55037",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38792,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55039",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38797,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55041",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38803,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55044",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38803,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55046",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.4355,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55048",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38803,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55053",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38802,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55054",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58032,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55058",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38801,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55122",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00525,
            "epssPercentile": 0.42664,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55131",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38792,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55136",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38791,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55137",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38791,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55138",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.43551,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55141",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38798,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55898",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00473,
            "epssPercentile": 0.3925,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55899",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38798,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55947",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55948",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55949",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38801,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58618",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38799,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-58618",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-microsoft-office-kb5002885",
      "slug": "microsoft-2026-07-microsoft-office-kb5002885",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002885",
      "title": "Deploy Microsoft Microsoft Office security update KB5002885",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002885",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft SharePoint Server 2019",
      "platform": "Microsoft Office",
      "release_version": "16.0.10417.20175",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 22 linked CVEs for Microsoft SharePoint Server 2019.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 22,
        "ids": [
          "CVE-2026-55023",
          "CVE-2026-55026",
          "CVE-2026-55027",
          "CVE-2026-55028",
          "CVE-2026-55032",
          "CVE-2026-55033",
          "CVE-2026-55035",
          "CVE-2026-55038",
          "CVE-2026-55045",
          "CVE-2026-55047",
          "CVE-2026-55050",
          "CVE-2026-55055",
          "CVE-2026-55121",
          "CVE-2026-55124",
          "CVE-2026-55125",
          "CVE-2026-55127",
          "CVE-2026-55128",
          "CVE-2026-55130",
          "CVE-2026-55132",
          "CVE-2026-55134",
          "CVE-2026-55142",
          "CVE-2026-56192"
        ],
        "details": [
          {
            "id": "CVE-2026-55023",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46271,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55026",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00449,
            "epssPercentile": 0.37607,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55027",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46272,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55028",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46271,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55032",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45122,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55033",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45123,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55035",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00574,
            "epssPercentile": 0.45266,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55038",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45122,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55045",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00446,
            "epssPercentile": 0.3738,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55047",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46272,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55050",
            "title": "Microsoft Word Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46271,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55055",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45123,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55121",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00513,
            "epssPercentile": 0.41842,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55124",
            "title": "Microsoft Word Information Disclosure Vulnerability",
            "summary": "Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46272,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55125",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45125,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55127",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45124,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55128",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45123,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55130",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45123,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55132",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45124,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55134",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45124,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55142",
            "title": "Microsoft Word Information Disclosure Vulnerability",
            "summary": "Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46273,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56192",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46273,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.4,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-55045",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-microsoft-office-kb5002886",
      "slug": "microsoft-2026-07-microsoft-office-kb5002886",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002886",
      "title": "Deploy Microsoft Microsoft Office security update KB5002886",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002886",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft Excel 2016 (32-bit edition), Microsoft Excel 2016 (64-bit edition)",
      "platform": "Microsoft Office",
      "release_version": "16.0.5561.1001",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 31 linked CVEs for Microsoft Excel 2016 (32-bit edition), Microsoft Excel 2016 (64-bit edition).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 31,
        "ids": [
          "CVE-2026-48580",
          "CVE-2026-50408",
          "CVE-2026-50675",
          "CVE-2026-50678",
          "CVE-2026-54988",
          "CVE-2026-55024",
          "CVE-2026-55025",
          "CVE-2026-55029",
          "CVE-2026-55031",
          "CVE-2026-55036",
          "CVE-2026-55037",
          "CVE-2026-55039",
          "CVE-2026-55041",
          "CVE-2026-55044",
          "CVE-2026-55046",
          "CVE-2026-55048",
          "CVE-2026-55053",
          "CVE-2026-55054",
          "CVE-2026-55058",
          "CVE-2026-55122",
          "CVE-2026-55131",
          "CVE-2026-55136",
          "CVE-2026-55137",
          "CVE-2026-55138",
          "CVE-2026-55141",
          "CVE-2026-55898",
          "CVE-2026-55899",
          "CVE-2026-55947",
          "CVE-2026-55948",
          "CVE-2026-55949",
          "CVE-2026-58618"
        ],
        "details": [
          {
            "id": "CVE-2026-48580",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.43549,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50408",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.4355,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50675",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38794,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50678",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00472,
            "epssPercentile": 0.39218,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54988",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00461,
            "epssPercentile": 0.38449,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55024",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38793,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55025",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38795,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55029",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38795,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55031",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38795,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55036",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38796,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55037",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38792,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55039",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38797,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55041",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38803,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55044",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38803,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55046",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.4355,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55048",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38803,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55053",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38802,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55054",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58032,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55058",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38801,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55122",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00525,
            "epssPercentile": 0.42664,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55131",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38792,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55136",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38791,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55137",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38791,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55138",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.43551,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55141",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38798,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55898",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00473,
            "epssPercentile": 0.3925,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55899",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38798,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55947",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55948",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55949",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38801,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58618",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38799,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-58618",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-microsoft-office-kb5002887",
      "slug": "microsoft-2026-07-microsoft-office-kb5002887",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002887",
      "title": "Deploy Microsoft Microsoft Office security update KB5002887",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002887",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition)",
      "platform": "Microsoft Office",
      "release_version": "16.0.5561.1000",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 23 linked CVEs for Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 23,
        "ids": [
          "CVE-2026-50301",
          "CVE-2026-50314",
          "CVE-2026-50467",
          "CVE-2026-50665",
          "CVE-2026-55018",
          "CVE-2026-55022",
          "CVE-2026-55023",
          "CVE-2026-55026",
          "CVE-2026-55027",
          "CVE-2026-55028",
          "CVE-2026-55035",
          "CVE-2026-55042",
          "CVE-2026-55045",
          "CVE-2026-55047",
          "CVE-2026-55056",
          "CVE-2026-55057",
          "CVE-2026-55121",
          "CVE-2026-55125",
          "CVE-2026-55129",
          "CVE-2026-55139",
          "CVE-2026-56192",
          "CVE-2026-56193",
          "CVE-2026-56195"
        ],
        "details": [
          {
            "id": "CVE-2026-50301",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38791,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50314",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38794,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50467",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.388,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50665",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00509,
            "epssPercentile": 0.41627,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55018",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.3879,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55022",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38799,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55023",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46271,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55026",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00449,
            "epssPercentile": 0.37607,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55027",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46272,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55028",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46271,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55035",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00574,
            "epssPercentile": 0.45266,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55042",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.43551,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55045",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00446,
            "epssPercentile": 0.3738,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55047",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46272,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55056",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55057",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.4355,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55121",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00513,
            "epssPercentile": 0.41842,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55125",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45125,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55129",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.3879,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55139",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00482,
            "epssPercentile": 0.3986,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56192",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46273,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56193",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00496,
            "epssPercentile": 0.40784,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56195",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.43549,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.4,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-55045",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-microsoft-office-kb5002890",
      "slug": "microsoft-2026-07-microsoft-office-kb5002890",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002890",
      "title": "Deploy Microsoft Microsoft Office security update KB5002890",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002890",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft Word 2016 (32-bit edition), Microsoft Word 2016 (64-bit edition)",
      "platform": "Microsoft Office",
      "release_version": "16.0.5561.1000",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 12 linked CVEs for Microsoft Word 2016 (32-bit edition), Microsoft Word 2016 (64-bit edition).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 12,
        "ids": [
          "CVE-2026-55032",
          "CVE-2026-55033",
          "CVE-2026-55038",
          "CVE-2026-55050",
          "CVE-2026-55055",
          "CVE-2026-55124",
          "CVE-2026-55127",
          "CVE-2026-55128",
          "CVE-2026-55130",
          "CVE-2026-55132",
          "CVE-2026-55134",
          "CVE-2026-55142"
        ],
        "details": [
          {
            "id": "CVE-2026-55032",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45122,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55033",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45123,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55038",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45122,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55050",
            "title": "Microsoft Word Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46271,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55055",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45123,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55124",
            "title": "Microsoft Word Information Disclosure Vulnerability",
            "summary": "Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46272,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55127",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45124,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55128",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45123,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55130",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45123,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55132",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45124,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55134",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45124,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55142",
            "title": "Microsoft Word Information Disclosure Vulnerability",
            "summary": "Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46273,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-55134",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-microsoft-office-kb5002891",
      "slug": "microsoft-2026-07-microsoft-office-kb5002891",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002891",
      "title": "Deploy Microsoft Microsoft Office security update KB5002891",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002891",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "platform": "Microsoft Office",
      "release_version": "16.0.5561.1001",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 38 linked CVEs for Microsoft SharePoint Enterprise Server 2016. Microsoft reports exploitation for CVE-2026-56164.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 38,
        "ids": [
          "CVE-2026-50522",
          "CVE-2026-54108",
          "CVE-2026-55016",
          "CVE-2026-55019",
          "CVE-2026-55020",
          "CVE-2026-55021",
          "CVE-2026-55023",
          "CVE-2026-55026",
          "CVE-2026-55027",
          "CVE-2026-55028",
          "CVE-2026-55030",
          "CVE-2026-55032",
          "CVE-2026-55033",
          "CVE-2026-55034",
          "CVE-2026-55035",
          "CVE-2026-55038",
          "CVE-2026-55040",
          "CVE-2026-55045",
          "CVE-2026-55047",
          "CVE-2026-55050",
          "CVE-2026-55051",
          "CVE-2026-55052",
          "CVE-2026-55055",
          "CVE-2026-55121",
          "CVE-2026-55124",
          "CVE-2026-55125",
          "CVE-2026-55126",
          "CVE-2026-55127",
          "CVE-2026-55128",
          "CVE-2026-55130",
          "CVE-2026-55132",
          "CVE-2026-55134",
          "CVE-2026-55135",
          "CVE-2026-55142",
          "CVE-2026-56157",
          "CVE-2026-56164",
          "CVE-2026-56192",
          "CVE-2026-58277"
        ],
        "details": [
          {
            "id": "CVE-2026-50522",
            "title": "Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
            "summary": "Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2026-07-22.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.84606,
            "epssPercentile": 0.99688,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2026-07-25 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54108",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01079,
            "epssPercentile": 0.62863,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55016",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00583,
            "epssPercentile": 0.45721,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55019",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00583,
            "epssPercentile": 0.45722,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55020",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00583,
            "epssPercentile": 0.45721,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55021",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00946,
            "epssPercentile": 0.58847,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55023",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46271,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55026",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00449,
            "epssPercentile": 0.37607,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55027",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46272,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55028",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46271,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55030",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00583,
            "epssPercentile": 0.45722,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55032",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45122,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55033",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45123,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55034",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00946,
            "epssPercentile": 0.58848,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55035",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00574,
            "epssPercentile": 0.45266,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55038",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45122,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55040",
            "title": "Microsoft SharePoint Weak Authentication Vulnerability",
            "summary": "Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 9.1,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2026-08-18.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.39652,
            "epssPercentile": 0.98521,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2026-08-21 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55045",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00446,
            "epssPercentile": 0.3738,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55047",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46272,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55050",
            "title": "Microsoft Word Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46271,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55051",
            "title": "Microsoft SharePoint Server Information Disclosure Vulnerability",
            "summary": "Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00911,
            "epssPercentile": 0.57717,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55052",
            "title": "Microsoft SharePoint Elevation of Privilege Vulnerability",
            "summary": "Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0094,
            "epssPercentile": 0.58631,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55055",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45123,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55121",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00513,
            "epssPercentile": 0.41842,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55124",
            "title": "Microsoft Word Information Disclosure Vulnerability",
            "summary": "Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46272,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55125",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45125,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55126",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00649,
            "epssPercentile": 0.48806,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55127",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45124,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55128",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45123,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55130",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45123,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55132",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45124,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55134",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45124,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55135",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00583,
            "epssPercentile": 0.45722,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55142",
            "title": "Microsoft Word Information Disclosure Vulnerability",
            "summary": "Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46273,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56157",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 5.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00496,
            "epssPercentile": 0.40764,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56164",
            "title": "Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability",
            "summary": "Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2026-07-14.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.26636,
            "epssPercentile": 0.97882,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2026-07-17 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56192",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46273,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58277",
            "title": "Microsoft SharePoint Elevation of Privilege Vulnerability",
            "summary": "Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0094,
            "epssPercentile": 0.58631,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Exploitation reported by the vendor source",
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-50522",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-microsoft-office-kb5002892",
      "slug": "microsoft-2026-07-microsoft-office-kb5002892",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002892",
      "title": "Deploy Microsoft Microsoft Office security update KB5002892",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002892",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "platform": "Microsoft Office",
      "release_version": "16.0.5561.1001",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 22 linked CVEs for Microsoft SharePoint Enterprise Server 2016.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 22,
        "ids": [
          "CVE-2026-55023",
          "CVE-2026-55026",
          "CVE-2026-55027",
          "CVE-2026-55028",
          "CVE-2026-55032",
          "CVE-2026-55033",
          "CVE-2026-55035",
          "CVE-2026-55038",
          "CVE-2026-55045",
          "CVE-2026-55047",
          "CVE-2026-55050",
          "CVE-2026-55055",
          "CVE-2026-55121",
          "CVE-2026-55124",
          "CVE-2026-55125",
          "CVE-2026-55127",
          "CVE-2026-55128",
          "CVE-2026-55130",
          "CVE-2026-55132",
          "CVE-2026-55134",
          "CVE-2026-55142",
          "CVE-2026-56192"
        ],
        "details": [
          {
            "id": "CVE-2026-55023",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46271,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55026",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00449,
            "epssPercentile": 0.37607,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55027",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46272,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55028",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46271,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55032",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45122,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55033",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45123,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55035",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00574,
            "epssPercentile": 0.45266,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55038",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45122,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55045",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00446,
            "epssPercentile": 0.3738,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55047",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46272,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55050",
            "title": "Microsoft Word Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46271,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55055",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45123,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55121",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00513,
            "epssPercentile": 0.41842,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55124",
            "title": "Microsoft Word Information Disclosure Vulnerability",
            "summary": "Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46272,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55125",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45125,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55127",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45124,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55128",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45123,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55130",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45123,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55132",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45124,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55134",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45124,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55142",
            "title": "Microsoft Word Information Disclosure Vulnerability",
            "summary": "Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46273,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56192",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46273,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.4,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-55045",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-microsoft-office-msrc-2026-07-microsoft-office-click-to-run-microsoft-365-apps-for-enterprise-for-32-bit-systems-microsoft-365-apps-for-enterprise-for-64-bit-systems-micr",
      "slug": "microsoft-2026-07-microsoft-office-msrc-2026-07-microsoft-office-click-to-run-microsoft-365-apps-for-enterprise-for-32-bit-systems-microsoft-365-apps-for-enterprise-for-64-bit-systems-micr",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-07-microsoft-office-click-to-run",
      "title": "Deploy Microsoft Microsoft Office update for Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office 2019 for 32-bit editions, plus 5 more",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://msrc.microsoft.com/update-guide/releaseNote/2026-Jul",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office 2019 for 32-bit editions, plus 5 more",
      "platform": "Microsoft Office",
      "release_version": "https://aka.ms/OfficeSecurityReleases",
      "action_type": "deploy-patch",
      "restart_required": "no",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 77 linked CVEs for Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office 2019 for 32-bit editions, plus 5 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 77,
        "ids": [
          "CVE-2026-47290",
          "CVE-2026-47642",
          "CVE-2026-48580",
          "CVE-2026-50301",
          "CVE-2026-50314",
          "CVE-2026-50408",
          "CVE-2026-50467",
          "CVE-2026-50665",
          "CVE-2026-50675",
          "CVE-2026-50678",
          "CVE-2026-54131",
          "CVE-2026-54988",
          "CVE-2026-55017",
          "CVE-2026-55018",
          "CVE-2026-55022",
          "CVE-2026-55023",
          "CVE-2026-55024",
          "CVE-2026-55025",
          "CVE-2026-55026",
          "CVE-2026-55027",
          "CVE-2026-55028",
          "CVE-2026-55029",
          "CVE-2026-55031",
          "CVE-2026-55032",
          "CVE-2026-55033",
          "CVE-2026-55035",
          "CVE-2026-55036",
          "CVE-2026-55037",
          "CVE-2026-55038",
          "CVE-2026-55039",
          "CVE-2026-55041",
          "CVE-2026-55042",
          "CVE-2026-55043",
          "CVE-2026-55044",
          "CVE-2026-55045",
          "CVE-2026-55046",
          "CVE-2026-55047",
          "CVE-2026-55048",
          "CVE-2026-55049",
          "CVE-2026-55050",
          "CVE-2026-55053",
          "CVE-2026-55054",
          "CVE-2026-55055",
          "CVE-2026-55056",
          "CVE-2026-55057",
          "CVE-2026-55058",
          "CVE-2026-55120",
          "CVE-2026-55121",
          "CVE-2026-55122",
          "CVE-2026-55123",
          "CVE-2026-55124",
          "CVE-2026-55125",
          "CVE-2026-55127",
          "CVE-2026-55128",
          "CVE-2026-55129",
          "CVE-2026-55130",
          "CVE-2026-55131",
          "CVE-2026-55132",
          "CVE-2026-55133",
          "CVE-2026-55134",
          "CVE-2026-55136",
          "CVE-2026-55137",
          "CVE-2026-55138",
          "CVE-2026-55139",
          "CVE-2026-55140",
          "CVE-2026-55141",
          "CVE-2026-55142",
          "CVE-2026-55898",
          "CVE-2026-55899",
          "CVE-2026-55947",
          "CVE-2026-55948",
          "CVE-2026-55949",
          "CVE-2026-56156",
          "CVE-2026-56192",
          "CVE-2026-56193",
          "CVE-2026-56195",
          "CVE-2026-58618"
        ],
        "details": [
          {
            "id": "CVE-2026-47290",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38798,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47642",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38796,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48580",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.43549,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50301",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38791,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50314",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38794,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50408",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.4355,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50467",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.388,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50665",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00509,
            "epssPercentile": 0.41627,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50675",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38794,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50678",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00472,
            "epssPercentile": 0.39218,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54131",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38792,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54988",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00461,
            "epssPercentile": 0.38449,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55017",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.3879,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55018",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.3879,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55022",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38799,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55023",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46271,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55024",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38793,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55025",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38795,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55026",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00449,
            "epssPercentile": 0.37607,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55027",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46272,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55028",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46271,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55029",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38795,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55031",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38795,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55032",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45122,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55033",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45123,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55035",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00574,
            "epssPercentile": 0.45266,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55036",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38796,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55037",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38792,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55038",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45122,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55039",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38797,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55041",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38803,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55042",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.43551,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55043",
            "title": "Microsoft PowerPoint Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55044",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38803,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55045",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00446,
            "epssPercentile": 0.3738,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55046",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.4355,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55047",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46272,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55048",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38803,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55049",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38803,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55050",
            "title": "Microsoft Word Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46271,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55053",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38802,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55054",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58032,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55055",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45123,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55056",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55057",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.4355,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55058",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38801,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55120",
            "title": "Microsoft PowerPoint Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38796,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55121",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00513,
            "epssPercentile": 0.41842,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55122",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00525,
            "epssPercentile": 0.42664,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55123",
            "title": "Microsoft PowerPoint Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38798,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55124",
            "title": "Microsoft Word Information Disclosure Vulnerability",
            "summary": "Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46272,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55125",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45125,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55127",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45124,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55128",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45123,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55129",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.3879,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55130",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45123,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55131",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38792,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55132",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45124,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55133",
            "title": "Microsoft OneNote Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office OneNote allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38789,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55134",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45124,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55136",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38791,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55137",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38791,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55138",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.43551,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55139",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00482,
            "epssPercentile": 0.3986,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55140",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38793,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55141",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38798,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55142",
            "title": "Microsoft Word Information Disclosure Vulnerability",
            "summary": "Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46273,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55898",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00473,
            "epssPercentile": 0.3925,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55899",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38798,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55947",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55948",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55949",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38801,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56156",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.388,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56192",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46273,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56193",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00496,
            "epssPercentile": 0.40784,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56195",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.43549,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58618",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38799,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.4,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-55045",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "The reviewed source does not require a restart.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-microsoft-office-msrc-2026-07-microsoft-office-release-notes-microsoft-office-365-for-mac",
      "slug": "microsoft-2026-07-microsoft-office-msrc-2026-07-microsoft-office-release-notes-microsoft-office-365-for-mac",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-07-microsoft-office-release-notes",
      "title": "Deploy Microsoft Microsoft Office update for Microsoft Office 365 for Mac",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://www.microsoft.com/en-us/microsoft-365/mac/microsoft-365-for-mac?msockid=35f9adb0e74b61392038b90de6fe608c",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft Office 365 for Mac",
      "platform": "Microsoft Office",
      "release_version": "16.111.26071215",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 74 linked CVEs for Microsoft Office 365 for Mac.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 74,
        "ids": [
          "CVE-2026-47642",
          "CVE-2026-48580",
          "CVE-2026-50314",
          "CVE-2026-50387",
          "CVE-2026-50408",
          "CVE-2026-50467",
          "CVE-2026-50665",
          "CVE-2026-50675",
          "CVE-2026-50678",
          "CVE-2026-54131",
          "CVE-2026-54988",
          "CVE-2026-55018",
          "CVE-2026-55022",
          "CVE-2026-55023",
          "CVE-2026-55024",
          "CVE-2026-55025",
          "CVE-2026-55026",
          "CVE-2026-55027",
          "CVE-2026-55028",
          "CVE-2026-55029",
          "CVE-2026-55031",
          "CVE-2026-55032",
          "CVE-2026-55033",
          "CVE-2026-55035",
          "CVE-2026-55036",
          "CVE-2026-55037",
          "CVE-2026-55038",
          "CVE-2026-55039",
          "CVE-2026-55041",
          "CVE-2026-55042",
          "CVE-2026-55043",
          "CVE-2026-55044",
          "CVE-2026-55045",
          "CVE-2026-55046",
          "CVE-2026-55047",
          "CVE-2026-55048",
          "CVE-2026-55049",
          "CVE-2026-55050",
          "CVE-2026-55053",
          "CVE-2026-55054",
          "CVE-2026-55055",
          "CVE-2026-55056",
          "CVE-2026-55057",
          "CVE-2026-55058",
          "CVE-2026-55120",
          "CVE-2026-55121",
          "CVE-2026-55122",
          "CVE-2026-55123",
          "CVE-2026-55124",
          "CVE-2026-55125",
          "CVE-2026-55127",
          "CVE-2026-55128",
          "CVE-2026-55129",
          "CVE-2026-55131",
          "CVE-2026-55132",
          "CVE-2026-55133",
          "CVE-2026-55134",
          "CVE-2026-55136",
          "CVE-2026-55137",
          "CVE-2026-55138",
          "CVE-2026-55139",
          "CVE-2026-55140",
          "CVE-2026-55141",
          "CVE-2026-55142",
          "CVE-2026-55898",
          "CVE-2026-55899",
          "CVE-2026-55947",
          "CVE-2026-55948",
          "CVE-2026-55949",
          "CVE-2026-56156",
          "CVE-2026-56192",
          "CVE-2026-56193",
          "CVE-2026-56195",
          "CVE-2026-58618"
        ],
        "details": [
          {
            "id": "CVE-2026-47642",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38796,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48580",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.43549,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50314",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38794,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50387",
            "title": "Windows GDI Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26111,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50408",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.4355,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50467",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.388,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50665",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00509,
            "epssPercentile": 0.41627,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50675",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38794,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50678",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00472,
            "epssPercentile": 0.39218,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54131",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38792,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54988",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00461,
            "epssPercentile": 0.38449,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55018",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.3879,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55022",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38799,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55023",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46271,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55024",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38793,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55025",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38795,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55026",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00449,
            "epssPercentile": 0.37607,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55027",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46272,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55028",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46271,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55029",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38795,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55031",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38795,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55032",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45122,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55033",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45123,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55035",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00574,
            "epssPercentile": 0.45266,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55036",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38796,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55037",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38792,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55038",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45122,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55039",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38797,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55041",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38803,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55042",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.43551,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55043",
            "title": "Microsoft PowerPoint Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55044",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38803,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55045",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00446,
            "epssPercentile": 0.3738,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55046",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.4355,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55047",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46272,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55048",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38803,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55049",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38803,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55050",
            "title": "Microsoft Word Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46271,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55053",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38802,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55054",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58032,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55055",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45123,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55056",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55057",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.4355,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55058",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38801,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55120",
            "title": "Microsoft PowerPoint Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38796,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55121",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00513,
            "epssPercentile": 0.41842,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55122",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00525,
            "epssPercentile": 0.42664,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55123",
            "title": "Microsoft PowerPoint Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38798,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55124",
            "title": "Microsoft Word Information Disclosure Vulnerability",
            "summary": "Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46272,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55125",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45125,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55127",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45124,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55128",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45123,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55129",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.3879,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55131",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38792,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55132",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45124,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55133",
            "title": "Microsoft OneNote Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office OneNote allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38789,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55134",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45124,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55136",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38791,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55137",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38791,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55138",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.43551,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55139",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00482,
            "epssPercentile": 0.3986,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55140",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38793,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55141",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38798,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55142",
            "title": "Microsoft Word Information Disclosure Vulnerability",
            "summary": "Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46273,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55898",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00473,
            "epssPercentile": 0.3925,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55899",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38798,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55947",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55948",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55949",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38801,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56156",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.388,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56192",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46273,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56193",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00496,
            "epssPercentile": 0.40784,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56195",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.43549,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58618",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38799,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.4,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-55045",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-microsoft-office-msrc-2026-07-microsoft-office-release-notes-microsoft-office-ltsc-for-mac-2021",
      "slug": "microsoft-2026-07-microsoft-office-msrc-2026-07-microsoft-office-release-notes-microsoft-office-ltsc-for-mac-2021",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-07-microsoft-office-release-notes",
      "title": "Deploy Microsoft Microsoft Office update for Microsoft Office LTSC for Mac 2021",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://go.microsoft.com/fwlink/p/?linkid=831049",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft Office LTSC for Mac 2021",
      "platform": "Microsoft Office",
      "release_version": "16.111.26071215",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 73 linked CVEs for Microsoft Office LTSC for Mac 2021.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 73,
        "ids": [
          "CVE-2026-47642",
          "CVE-2026-48580",
          "CVE-2026-50314",
          "CVE-2026-50387",
          "CVE-2026-50408",
          "CVE-2026-50467",
          "CVE-2026-50665",
          "CVE-2026-50675",
          "CVE-2026-50678",
          "CVE-2026-54131",
          "CVE-2026-54988",
          "CVE-2026-55018",
          "CVE-2026-55022",
          "CVE-2026-55023",
          "CVE-2026-55024",
          "CVE-2026-55025",
          "CVE-2026-55026",
          "CVE-2026-55027",
          "CVE-2026-55028",
          "CVE-2026-55029",
          "CVE-2026-55031",
          "CVE-2026-55032",
          "CVE-2026-55033",
          "CVE-2026-55035",
          "CVE-2026-55036",
          "CVE-2026-55037",
          "CVE-2026-55038",
          "CVE-2026-55039",
          "CVE-2026-55041",
          "CVE-2026-55042",
          "CVE-2026-55043",
          "CVE-2026-55044",
          "CVE-2026-55045",
          "CVE-2026-55046",
          "CVE-2026-55047",
          "CVE-2026-55048",
          "CVE-2026-55049",
          "CVE-2026-55050",
          "CVE-2026-55053",
          "CVE-2026-55054",
          "CVE-2026-55055",
          "CVE-2026-55056",
          "CVE-2026-55057",
          "CVE-2026-55058",
          "CVE-2026-55120",
          "CVE-2026-55121",
          "CVE-2026-55122",
          "CVE-2026-55123",
          "CVE-2026-55124",
          "CVE-2026-55125",
          "CVE-2026-55127",
          "CVE-2026-55128",
          "CVE-2026-55129",
          "CVE-2026-55131",
          "CVE-2026-55132",
          "CVE-2026-55133",
          "CVE-2026-55134",
          "CVE-2026-55136",
          "CVE-2026-55137",
          "CVE-2026-55138",
          "CVE-2026-55139",
          "CVE-2026-55140",
          "CVE-2026-55141",
          "CVE-2026-55898",
          "CVE-2026-55899",
          "CVE-2026-55947",
          "CVE-2026-55948",
          "CVE-2026-55949",
          "CVE-2026-56156",
          "CVE-2026-56192",
          "CVE-2026-56193",
          "CVE-2026-56195",
          "CVE-2026-58618"
        ],
        "details": [
          {
            "id": "CVE-2026-47642",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38796,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48580",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.43549,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50314",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38794,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50387",
            "title": "Windows GDI Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26111,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50408",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.4355,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50467",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.388,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50665",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00509,
            "epssPercentile": 0.41627,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50675",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38794,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50678",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00472,
            "epssPercentile": 0.39218,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54131",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38792,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54988",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00461,
            "epssPercentile": 0.38449,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55018",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.3879,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55022",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38799,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55023",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46271,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55024",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38793,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55025",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38795,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55026",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00449,
            "epssPercentile": 0.37607,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55027",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46272,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55028",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46271,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55029",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38795,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55031",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38795,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55032",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45122,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55033",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45123,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55035",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00574,
            "epssPercentile": 0.45266,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55036",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38796,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55037",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38792,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55038",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45122,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55039",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38797,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55041",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38803,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55042",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.43551,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55043",
            "title": "Microsoft PowerPoint Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55044",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38803,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55045",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00446,
            "epssPercentile": 0.3738,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55046",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.4355,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55047",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46272,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55048",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38803,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55049",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38803,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55050",
            "title": "Microsoft Word Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46271,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55053",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38802,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55054",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58032,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55055",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45123,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55056",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55057",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.4355,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55058",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38801,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55120",
            "title": "Microsoft PowerPoint Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38796,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55121",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00513,
            "epssPercentile": 0.41842,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55122",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00525,
            "epssPercentile": 0.42664,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55123",
            "title": "Microsoft PowerPoint Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38798,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55124",
            "title": "Microsoft Word Information Disclosure Vulnerability",
            "summary": "Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46272,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55125",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45125,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55127",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45124,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55128",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45123,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55129",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.3879,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55131",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38792,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55132",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45124,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55133",
            "title": "Microsoft OneNote Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office OneNote allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38789,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55134",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45124,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55136",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38791,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55137",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38791,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55138",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.43551,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55139",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00482,
            "epssPercentile": 0.3986,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55140",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38793,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55141",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38798,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55898",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00473,
            "epssPercentile": 0.3925,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55899",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38798,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55947",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55948",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55949",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38801,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56156",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.388,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56192",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46273,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56193",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00496,
            "epssPercentile": 0.40784,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56195",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.43549,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58618",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38799,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.4,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-55045",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-microsoft-office-msrc-2026-07-microsoft-office-release-notes-microsoft-office-ltsc-for-mac-2024",
      "slug": "microsoft-2026-07-microsoft-office-msrc-2026-07-microsoft-office-release-notes-microsoft-office-ltsc-for-mac-2024",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-07-microsoft-office-release-notes",
      "title": "Deploy Microsoft Microsoft Office update for Microsoft Office LTSC for Mac 2024",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://go.microsoft.com/fwlink/p/?linkid=831049",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft Office LTSC for Mac 2024",
      "platform": "Microsoft Office",
      "release_version": "16.111.26071215",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 73 linked CVEs for Microsoft Office LTSC for Mac 2024.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 73,
        "ids": [
          "CVE-2026-47642",
          "CVE-2026-48580",
          "CVE-2026-50314",
          "CVE-2026-50387",
          "CVE-2026-50408",
          "CVE-2026-50467",
          "CVE-2026-50665",
          "CVE-2026-50675",
          "CVE-2026-50678",
          "CVE-2026-54131",
          "CVE-2026-54988",
          "CVE-2026-55018",
          "CVE-2026-55022",
          "CVE-2026-55023",
          "CVE-2026-55024",
          "CVE-2026-55025",
          "CVE-2026-55026",
          "CVE-2026-55027",
          "CVE-2026-55028",
          "CVE-2026-55029",
          "CVE-2026-55031",
          "CVE-2026-55032",
          "CVE-2026-55033",
          "CVE-2026-55035",
          "CVE-2026-55036",
          "CVE-2026-55037",
          "CVE-2026-55038",
          "CVE-2026-55039",
          "CVE-2026-55041",
          "CVE-2026-55042",
          "CVE-2026-55043",
          "CVE-2026-55044",
          "CVE-2026-55045",
          "CVE-2026-55046",
          "CVE-2026-55047",
          "CVE-2026-55048",
          "CVE-2026-55049",
          "CVE-2026-55050",
          "CVE-2026-55053",
          "CVE-2026-55054",
          "CVE-2026-55055",
          "CVE-2026-55056",
          "CVE-2026-55057",
          "CVE-2026-55058",
          "CVE-2026-55120",
          "CVE-2026-55121",
          "CVE-2026-55122",
          "CVE-2026-55123",
          "CVE-2026-55124",
          "CVE-2026-55125",
          "CVE-2026-55127",
          "CVE-2026-55128",
          "CVE-2026-55129",
          "CVE-2026-55131",
          "CVE-2026-55132",
          "CVE-2026-55133",
          "CVE-2026-55134",
          "CVE-2026-55136",
          "CVE-2026-55137",
          "CVE-2026-55138",
          "CVE-2026-55139",
          "CVE-2026-55140",
          "CVE-2026-55141",
          "CVE-2026-55898",
          "CVE-2026-55899",
          "CVE-2026-55947",
          "CVE-2026-55948",
          "CVE-2026-55949",
          "CVE-2026-56156",
          "CVE-2026-56192",
          "CVE-2026-56193",
          "CVE-2026-56195",
          "CVE-2026-58618"
        ],
        "details": [
          {
            "id": "CVE-2026-47642",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38796,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48580",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.43549,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50314",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38794,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50387",
            "title": "Windows GDI Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26111,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50408",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.4355,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50467",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.388,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50665",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00509,
            "epssPercentile": 0.41627,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50675",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38794,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50678",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00472,
            "epssPercentile": 0.39218,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54131",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38792,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54988",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00461,
            "epssPercentile": 0.38449,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55018",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.3879,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55022",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38799,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55023",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46271,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55024",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38793,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55025",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38795,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55026",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00449,
            "epssPercentile": 0.37607,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55027",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46272,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55028",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46271,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55029",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38795,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55031",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38795,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55032",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45122,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55033",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45123,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55035",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00574,
            "epssPercentile": 0.45266,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55036",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38796,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55037",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38792,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55038",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45122,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55039",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38797,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55041",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38803,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55042",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.43551,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55043",
            "title": "Microsoft PowerPoint Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55044",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38803,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55045",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00446,
            "epssPercentile": 0.3738,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55046",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.4355,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55047",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46272,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55048",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38803,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55049",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38803,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55050",
            "title": "Microsoft Word Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46271,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55053",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38802,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55054",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58032,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55055",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45123,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55056",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55057",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.4355,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55058",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38801,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55120",
            "title": "Microsoft PowerPoint Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38796,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55121",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00513,
            "epssPercentile": 0.41842,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55122",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00525,
            "epssPercentile": 0.42664,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55123",
            "title": "Microsoft PowerPoint Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38798,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55124",
            "title": "Microsoft Word Information Disclosure Vulnerability",
            "summary": "Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46272,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55125",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45125,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55127",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45124,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55128",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45123,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55129",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.3879,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55131",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38792,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55132",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45124,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55133",
            "title": "Microsoft OneNote Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office OneNote allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38789,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55134",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00571,
            "epssPercentile": 0.45124,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55136",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38791,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55137",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38791,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55138",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.43551,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55139",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00482,
            "epssPercentile": 0.3986,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55140",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38793,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55141",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38798,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55898",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00473,
            "epssPercentile": 0.3925,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55899",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38798,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55947",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55948",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55949",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38801,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56156",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.388,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56192",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00595,
            "epssPercentile": 0.46273,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56193",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00496,
            "epssPercentile": 0.40784,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56195",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.43549,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58618",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38799,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.4,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-55045",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-microsoft-office-msrc-2026-07-microsoft-office-release-notes-microsoft-office-for-android",
      "slug": "microsoft-2026-07-microsoft-office-msrc-2026-07-microsoft-office-release-notes-microsoft-office-for-android",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-07-microsoft-office-release-notes",
      "title": "Deploy Microsoft Microsoft Office update for Microsoft Office for Android",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://play.google.com/store/apps/details?id=com.microsoft.office.officehubrow",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft Office for Android",
      "platform": "Microsoft Office",
      "release_version": "16.0.20228.20042",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Office for Android.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-50387"
        ],
        "details": [
          {
            "id": "CVE-2026-50387",
            "title": "Windows GDI Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26111,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-50387",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-open-source-software-msrc-2026-07-open-source-software-release-notes-windows-subsystem-for-linux-wsl2",
      "slug": "microsoft-2026-07-open-source-software-msrc-2026-07-open-source-software-release-notes-windows-subsystem-for-linux-wsl2",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-07-open-source-software-release-notes",
      "title": "Deploy Microsoft Open Source Software update for Windows Subsystem for Linux (WSL2)",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://learn.microsoft.com/en-us/windows/wsl/install",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Windows Subsystem for Linux (WSL2)",
      "platform": "Open Source Software",
      "release_version": "2.7.10, 2.7.8",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Windows Subsystem for Linux (WSL2).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 2,
        "ids": [
          "CVE-2026-57968",
          "CVE-2026-57973"
        ],
        "details": [
          {
            "id": "CVE-2026-57968",
            "title": "Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability",
            "summary": "Buffer over-read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26094,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57973",
            "title": "Windows Subsystem for Linux (WSL2) Kernel Tampering Vulnerability",
            "summary": "Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to perform tampering locally.",
            "score": 6.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00217,
            "epssPercentile": 0.12027,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-57968",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-other-msrc-2026-07-other-1-13-0-251-github-copilot-plugin-for-jetbrains-ides",
      "slug": "microsoft-2026-07-other-msrc-2026-07-other-1-13-0-251-github-copilot-plugin-for-jetbrains-ides",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-07-other-1-13-0-251",
      "title": "Deploy Microsoft Other update for GitHub Copilot Plugin for JetBrains IDEs",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://plugins.jetbrains.com/plugin/17718-github-copilot--your-ai-pair-programmer/versions/stable/1103496",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "GitHub Copilot Plugin for JetBrains IDEs",
      "platform": "Other",
      "release_version": "1.13.0-251",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for GitHub Copilot Plugin for JetBrains IDEs.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-50510"
        ],
        "details": [
          {
            "id": "CVE-2026-50510",
            "title": "GitHub Copilot Remote Code Execution Vulnerability",
            "summary": "Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.2898,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-50510",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-other-msrc-2026-07-other-release-notes-age-of-empires-ii-definitive-edition-game",
      "slug": "microsoft-2026-07-other-msrc-2026-07-other-release-notes-age-of-empires-ii-definitive-edition-game",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-07-other-release-notes",
      "title": "Deploy Microsoft Other update for Age of Empires II: Definitive Edition Game",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://www.ageofempires.com/news/age-of-empires-ii-definitive-edition-update-177723/",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Age of Empires II: Definitive Edition Game",
      "platform": "Other",
      "release_version": "101.103.46651.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Age of Empires II: Definitive Edition Game.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-50663"
        ],
        "details": [
          {
            "id": "CVE-2026-50663",
            "title": "Game: Age of Empires II: Definitive Edition Remote Code Execution Vulnerability",
            "summary": "Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00939,
            "epssPercentile": 0.58611,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-50663",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-sql-server-kb5101346",
      "slug": "microsoft-2026-07-sql-server-kb5101346",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5101346",
      "title": "Deploy Microsoft SQL Server security update KB5101346",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5101346",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft SQL Server 2025 for x64-based Systems (CU6)",
      "platform": "SQL Server",
      "release_version": "17.0.4060.2",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 7 linked CVEs for Microsoft SQL Server 2025 for x64-based Systems (CU6).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 7,
        "ids": [
          "CVE-2026-47295",
          "CVE-2026-47296",
          "CVE-2026-50468",
          "CVE-2026-54116",
          "CVE-2026-54117",
          "CVE-2026-54118",
          "CVE-2026-55002"
        ],
        "details": [
          {
            "id": "CVE-2026-47295",
            "title": "Microsoft SQL Server Elevation of Privilege Vulnerability",
            "summary": "Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00987,
            "epssPercentile": 0.60163,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47296",
            "title": "Microsoft SQL Server Elevation of Privilege Vulnerability",
            "summary": "Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00497,
            "epssPercentile": 0.40835,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50468",
            "title": "Microsoft SQL Server Information Disclosure Vulnerability",
            "summary": "Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00995,
            "epssPercentile": 0.60374,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54116",
            "title": "Microsoft SQL Server Information Disclosure Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00995,
            "epssPercentile": 0.60375,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54117",
            "title": "Microsoft SQL Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01164,
            "epssPercentile": 0.6522,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54118",
            "title": "Microsoft SQL Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01164,
            "epssPercentile": 0.65219,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55002",
            "title": "Microsoft SQL Server Elevation of Privilege Vulnerability",
            "summary": "External control of file name or path in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00618,
            "epssPercentile": 0.47376,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-54118",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-sql-server-kb5101347",
      "slug": "microsoft-2026-07-sql-server-kb5101347",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5101347",
      "title": "Deploy Microsoft SQL Server security update KB5101347",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5101347",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft SQL Server 2022 for x64-based Systems (CU 25)",
      "platform": "SQL Server",
      "release_version": "16.0.4262.2",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 4 linked CVEs for Microsoft SQL Server 2022 for x64-based Systems (CU 25).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 4,
        "ids": [
          "CVE-2026-47295",
          "CVE-2026-47296",
          "CVE-2026-54118",
          "CVE-2026-55002"
        ],
        "details": [
          {
            "id": "CVE-2026-47295",
            "title": "Microsoft SQL Server Elevation of Privilege Vulnerability",
            "summary": "Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00987,
            "epssPercentile": 0.60163,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47296",
            "title": "Microsoft SQL Server Elevation of Privilege Vulnerability",
            "summary": "Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00497,
            "epssPercentile": 0.40835,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54118",
            "title": "Microsoft SQL Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01164,
            "epssPercentile": 0.65219,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55002",
            "title": "Microsoft SQL Server Elevation of Privilege Vulnerability",
            "summary": "External control of file name or path in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00618,
            "epssPercentile": 0.47376,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-54118",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-sql-server-kb5102333",
      "slug": "microsoft-2026-07-sql-server-kb5102333",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5102333",
      "title": "Deploy Microsoft SQL Server security update KB5102333",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5102333",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft SQL Server 2025 for x64-based Systems (GDR)",
      "platform": "SQL Server",
      "release_version": "17.0.1125.2",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 7 linked CVEs for Microsoft SQL Server 2025 for x64-based Systems (GDR).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 7,
        "ids": [
          "CVE-2026-47295",
          "CVE-2026-47296",
          "CVE-2026-50468",
          "CVE-2026-54116",
          "CVE-2026-54117",
          "CVE-2026-54118",
          "CVE-2026-55002"
        ],
        "details": [
          {
            "id": "CVE-2026-47295",
            "title": "Microsoft SQL Server Elevation of Privilege Vulnerability",
            "summary": "Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00987,
            "epssPercentile": 0.60163,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47296",
            "title": "Microsoft SQL Server Elevation of Privilege Vulnerability",
            "summary": "Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00497,
            "epssPercentile": 0.40835,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50468",
            "title": "Microsoft SQL Server Information Disclosure Vulnerability",
            "summary": "Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00995,
            "epssPercentile": 0.60374,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54116",
            "title": "Microsoft SQL Server Information Disclosure Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00995,
            "epssPercentile": 0.60375,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54117",
            "title": "Microsoft SQL Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01164,
            "epssPercentile": 0.6522,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54118",
            "title": "Microsoft SQL Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01164,
            "epssPercentile": 0.65219,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55002",
            "title": "Microsoft SQL Server Elevation of Privilege Vulnerability",
            "summary": "External control of file name or path in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00618,
            "epssPercentile": 0.47376,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-54118",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-sql-server-kb5102334",
      "slug": "microsoft-2026-07-sql-server-kb5102334",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5102334",
      "title": "Deploy Microsoft SQL Server security update KB5102334",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5102334",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft SQL Server 2022 for x64-based Systems (GDR)",
      "platform": "SQL Server",
      "release_version": "16.0.1190.2",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 4 linked CVEs for Microsoft SQL Server 2022 for x64-based Systems (GDR).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 4,
        "ids": [
          "CVE-2026-47295",
          "CVE-2026-47296",
          "CVE-2026-54118",
          "CVE-2026-55002"
        ],
        "details": [
          {
            "id": "CVE-2026-47295",
            "title": "Microsoft SQL Server Elevation of Privilege Vulnerability",
            "summary": "Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00987,
            "epssPercentile": 0.60163,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47296",
            "title": "Microsoft SQL Server Elevation of Privilege Vulnerability",
            "summary": "Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00497,
            "epssPercentile": 0.40835,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54118",
            "title": "Microsoft SQL Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01164,
            "epssPercentile": 0.65219,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55002",
            "title": "Microsoft SQL Server Elevation of Privilege Vulnerability",
            "summary": "External control of file name or path in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00618,
            "epssPercentile": 0.47376,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-54118",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-sql-server-kb5102335",
      "slug": "microsoft-2026-07-sql-server-kb5102335",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5102335",
      "title": "Deploy Microsoft SQL Server security update KB5102335",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5102335",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft SQL Server 2019 for x64-based Systems (CU 32)",
      "platform": "SQL Server",
      "release_version": "15.0.4480.2",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 4 linked CVEs for Microsoft SQL Server 2019 for x64-based Systems (CU 32).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 4,
        "ids": [
          "CVE-2026-47295",
          "CVE-2026-47296",
          "CVE-2026-54118",
          "CVE-2026-55002"
        ],
        "details": [
          {
            "id": "CVE-2026-47295",
            "title": "Microsoft SQL Server Elevation of Privilege Vulnerability",
            "summary": "Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00987,
            "epssPercentile": 0.60163,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47296",
            "title": "Microsoft SQL Server Elevation of Privilege Vulnerability",
            "summary": "Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00497,
            "epssPercentile": 0.40835,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54118",
            "title": "Microsoft SQL Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01164,
            "epssPercentile": 0.65219,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55002",
            "title": "Microsoft SQL Server Elevation of Privilege Vulnerability",
            "summary": "External control of file name or path in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00618,
            "epssPercentile": 0.47376,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-54118",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-sql-server-kb5102336",
      "slug": "microsoft-2026-07-sql-server-kb5102336",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5102336",
      "title": "Deploy Microsoft SQL Server security update KB5102336",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5102336",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft SQL Server 2019 for x64-based Systems (GDR)",
      "platform": "SQL Server",
      "release_version": "15.0.2180.2",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 4 linked CVEs for Microsoft SQL Server 2019 for x64-based Systems (GDR).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 4,
        "ids": [
          "CVE-2026-47295",
          "CVE-2026-47296",
          "CVE-2026-54118",
          "CVE-2026-55002"
        ],
        "details": [
          {
            "id": "CVE-2026-47295",
            "title": "Microsoft SQL Server Elevation of Privilege Vulnerability",
            "summary": "Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00987,
            "epssPercentile": 0.60163,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47296",
            "title": "Microsoft SQL Server Elevation of Privilege Vulnerability",
            "summary": "Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00497,
            "epssPercentile": 0.40835,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54118",
            "title": "Microsoft SQL Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01164,
            "epssPercentile": 0.65219,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55002",
            "title": "Microsoft SQL Server Elevation of Privilege Vulnerability",
            "summary": "External control of file name or path in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00618,
            "epssPercentile": 0.47376,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-54118",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-sql-server-kb5102337",
      "slug": "microsoft-2026-07-sql-server-kb5102337",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5102337",
      "title": "Deploy Microsoft SQL Server security update KB5102337",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5102337",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft SQL Server 2017 for x64-based Systems (CU 31)",
      "platform": "SQL Server",
      "release_version": "14.0.3540.1",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 4 linked CVEs for Microsoft SQL Server 2017 for x64-based Systems (CU 31).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 4,
        "ids": [
          "CVE-2026-47295",
          "CVE-2026-47296",
          "CVE-2026-54118",
          "CVE-2026-55002"
        ],
        "details": [
          {
            "id": "CVE-2026-47295",
            "title": "Microsoft SQL Server Elevation of Privilege Vulnerability",
            "summary": "Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00987,
            "epssPercentile": 0.60163,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47296",
            "title": "Microsoft SQL Server Elevation of Privilege Vulnerability",
            "summary": "Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00497,
            "epssPercentile": 0.40835,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54118",
            "title": "Microsoft SQL Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01164,
            "epssPercentile": 0.65219,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55002",
            "title": "Microsoft SQL Server Elevation of Privilege Vulnerability",
            "summary": "External control of file name or path in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00618,
            "epssPercentile": 0.47376,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-54118",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-sql-server-kb5102338",
      "slug": "microsoft-2026-07-sql-server-kb5102338",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5102338",
      "title": "Deploy Microsoft SQL Server security update KB5102338",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5102338",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft SQL Server 2017 for x64-based Systems (GDR)",
      "platform": "SQL Server",
      "release_version": "14.0.2120.1",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 4 linked CVEs for Microsoft SQL Server 2017 for x64-based Systems (GDR).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 4,
        "ids": [
          "CVE-2026-47295",
          "CVE-2026-47296",
          "CVE-2026-54118",
          "CVE-2026-55002"
        ],
        "details": [
          {
            "id": "CVE-2026-47295",
            "title": "Microsoft SQL Server Elevation of Privilege Vulnerability",
            "summary": "Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00987,
            "epssPercentile": 0.60163,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47296",
            "title": "Microsoft SQL Server Elevation of Privilege Vulnerability",
            "summary": "Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00497,
            "epssPercentile": 0.40835,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54118",
            "title": "Microsoft SQL Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01164,
            "epssPercentile": 0.65219,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55002",
            "title": "Microsoft SQL Server Elevation of Privilege Vulnerability",
            "summary": "External control of file name or path in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00618,
            "epssPercentile": 0.47376,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-54118",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-sql-server-kb5102339",
      "slug": "microsoft-2026-07-sql-server-kb5102339",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5102339",
      "title": "Deploy Microsoft SQL Server security update KB5102339",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5102339",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature Pack",
      "platform": "SQL Server",
      "release_version": "13.0.7095.1",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 4 linked CVEs for Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature Pack.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 4,
        "ids": [
          "CVE-2026-47295",
          "CVE-2026-47296",
          "CVE-2026-54118",
          "CVE-2026-55002"
        ],
        "details": [
          {
            "id": "CVE-2026-47295",
            "title": "Microsoft SQL Server Elevation of Privilege Vulnerability",
            "summary": "Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00987,
            "epssPercentile": 0.60163,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47296",
            "title": "Microsoft SQL Server Elevation of Privilege Vulnerability",
            "summary": "Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00497,
            "epssPercentile": 0.40835,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54118",
            "title": "Microsoft SQL Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01164,
            "epssPercentile": 0.65219,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55002",
            "title": "Microsoft SQL Server Elevation of Privilege Vulnerability",
            "summary": "External control of file name or path in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00618,
            "epssPercentile": 0.47376,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-54118",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-sql-server-kb5102340",
      "slug": "microsoft-2026-07-sql-server-kb5102340",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5102340",
      "title": "Deploy Microsoft SQL Server security update KB5102340",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5102340",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 (GDR)",
      "platform": "SQL Server",
      "release_version": "13.0.6500.1",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 4 linked CVEs for Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 (GDR).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 4,
        "ids": [
          "CVE-2026-47295",
          "CVE-2026-47296",
          "CVE-2026-54118",
          "CVE-2026-55002"
        ],
        "details": [
          {
            "id": "CVE-2026-47295",
            "title": "Microsoft SQL Server Elevation of Privilege Vulnerability",
            "summary": "Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00987,
            "epssPercentile": 0.60163,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47296",
            "title": "Microsoft SQL Server Elevation of Privilege Vulnerability",
            "summary": "Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00497,
            "epssPercentile": 0.40835,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54118",
            "title": "Microsoft SQL Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01164,
            "epssPercentile": 0.65219,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55002",
            "title": "Microsoft SQL Server Elevation of Privilege Vulnerability",
            "summary": "External control of file name or path in SQL Server allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00618,
            "epssPercentile": 0.47376,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-54118",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-sql-server-msrc-2026-07-sql-server-release-notes-power-bi-report-server",
      "slug": "microsoft-2026-07-sql-server-msrc-2026-07-sql-server-release-notes-power-bi-report-server",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-07-sql-server-release-notes",
      "title": "Deploy Microsoft SQL Server update for Power BI Report Server",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://www.microsoft.com/en-us/download/details.aspx?id=105944",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Power BI Report Server",
      "platform": "SQL Server",
      "release_version": "1.26.9682.1442",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Power BI Report Server.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-58647"
        ],
        "details": [
          {
            "id": "CVE-2026-58647",
            "title": "Microsoft PowerBI Report Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing over a network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00348,
            "epssPercentile": 0.2782,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-58647",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-server-software-kb5103212",
      "slug": "microsoft-2026-07-server-software-kb5103212",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5103212",
      "title": "Deploy Microsoft Server Software security update KB5103212",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5103212",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft Exchange Server Subscription Edition RTM",
      "platform": "Server Software",
      "release_version": "15.02.2562.045",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 4 linked CVEs for Microsoft Exchange Server Subscription Edition RTM.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 4,
        "ids": [
          "CVE-2026-55005",
          "CVE-2026-55006",
          "CVE-2026-55008",
          "CVE-2026-55009"
        ],
        "details": [
          {
            "id": "CVE-2026-55005",
            "title": "Microsoft Exchange Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.57789,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55006",
            "title": "Microsoft Exchange Server Elevation of Privilege Vulnerability",
            "summary": "Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55008",
            "title": "Microsoft Exchange Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.",
            "score": 9.6,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00863,
            "epssPercentile": 0.56246,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55009",
            "title": "Microsoft Exchange Server Elevation of Privilege Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02513,
            "epssPercentile": 0.83741,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.6,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-55008",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-system-center-msrc-2026-07-system-center-kb38232642-microsoft-configuration-manager-2503",
      "slug": "microsoft-2026-07-system-center-msrc-2026-07-system-center-kb38232642-microsoft-configuration-manager-2503",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-07-system-center-kb38232642",
      "title": "Deploy Microsoft System Center update for Microsoft Configuration Manager 2503",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://learn.microsoft.com/en-us/intune/configmgr/hotfix/2603/38232642",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft Configuration Manager 2503",
      "platform": "System Center",
      "release_version": "5.0.9135.1031",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Configuration Manager 2503.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-47301"
        ],
        "details": [
          {
            "id": "CVE-2026-47301",
            "title": "Configuration Manager Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00964,
            "epssPercentile": 0.5939,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-47301",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-system-center-msrc-2026-07-system-center-release-notes-microsoft-defender-for-endpoint-for-mac",
      "slug": "microsoft-2026-07-system-center-msrc-2026-07-system-center-release-notes-microsoft-defender-for-endpoint-for-mac",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-07-system-center-release-notes",
      "title": "Deploy Microsoft System Center update for Microsoft Defender for Endpoint for Mac",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/mac-updates?view=o365-worldwide",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft Defender for Endpoint for Mac",
      "platform": "System Center",
      "release_version": "101.26042.0020",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft Defender for Endpoint for Mac.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 3,
        "ids": [
          "CVE-2026-50657",
          "CVE-2026-50658",
          "CVE-2026-56178"
        ],
        "details": [
          {
            "id": "CVE-2026-50657",
            "title": "Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability",
            "summary": "Exposure of private personal information to an unauthorized actor in Microsoft Defender allows an authorized attacker to disclose information locally.",
            "score": 4.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.004,
            "epssPercentile": 0.33313,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50658",
            "title": "Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability",
            "summary": "Time-of-check time-of-use (toctou) race condition in Microsoft Defender allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10169,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56178",
            "title": "Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability",
            "summary": "Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00233,
            "epssPercentile": 0.14124,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-50658",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-system-center-msrc-2026-07-system-center-release-notes-microsoft-malware-protection-engine",
      "slug": "microsoft-2026-07-system-center-msrc-2026-07-system-center-release-notes-microsoft-malware-protection-engine",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-07-system-center-release-notes",
      "title": "Deploy Microsoft System Center update for Microsoft Malware Protection Engine",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://msrc.microsoft.com/update-guide/releaseNote/2026-Jul",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft Malware Protection Engine",
      "platform": "System Center",
      "release_version": "1.1.26060.3008",
      "action_type": "deploy-patch",
      "restart_required": "no",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Microsoft Malware Protection Engine.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 2,
        "ids": [
          "CVE-2026-55011",
          "CVE-2026-55012"
        ],
        "details": [
          {
            "id": "CVE-2026-55011",
            "title": "Microsoft Defender Remote Code Execution Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00374,
            "epssPercentile": 0.30548,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55012",
            "title": "Microsoft Defender Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Defender allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00374,
            "epssPercentile": 0.30548,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-55012",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "The reviewed source does not require a restart.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-windows-kb5089548",
      "slug": "microsoft-2026-07-windows-kb5089548",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5089548",
      "title": "Deploy Microsoft Windows security update KB5089548",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5089548",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Windows 11 Version 26H1 for ARM64-based Systems",
      "platform": "Windows",
      "release_version": "10.0.28000.2113",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows 11 Version 26H1 for ARM64-based Systems.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-34348"
        ],
        "details": [
          {
            "id": "CVE-2026-34348",
            "title": "Windows Event Logging Service Information Disclosure Vulnerability",
            "summary": "Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00907,
            "epssPercentile": 0.57588,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 6.5,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-34348",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-windows-kb5095051",
      "slug": "microsoft-2026-07-windows-kb5095051",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5095051",
      "title": "Deploy Microsoft Windows security update KB5095051",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5095051",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Windows 11 Version 26H1 for ARM64-based Systems",
      "platform": "Windows",
      "release_version": "10.0.28000.2269",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 6 linked CVEs for Windows 11 Version 26H1 for ARM64-based Systems.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 6,
        "ids": [
          "CVE-2026-40378",
          "CVE-2026-42982",
          "CVE-2026-42990",
          "CVE-2026-44800",
          "CVE-2026-48571",
          "CVE-2026-48572"
        ],
        "details": [
          {
            "id": "CVE-2026-40378",
            "title": "Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability",
            "summary": "Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65473,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-42982",
            "title": "Windows Secure Kernel Mode Elevation of Privilege Vulnerability",
            "summary": "Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26114,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-42990",
            "title": "SQL Server ODBC driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59786,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-44800",
            "title": "Windows Push Notifications Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.1017,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48571",
            "title": "Windows App Package Installer Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18081,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48572",
            "title": "Windows App Package Installer Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10166,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-42990",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-windows-kb5099414",
      "slug": "microsoft-2026-07-windows-kb5099414",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5099414",
      "title": "Deploy Microsoft Windows security update KB5099414",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5099414",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Windows 11 Version 23H2 for ARM64-based Systems, Windows 11 Version 23H2 for x64-based Systems",
      "platform": "Windows",
      "release_version": "10.0.22631.7376",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 16 linked CVEs for Windows 11 Version 23H2 for ARM64-based Systems, Windows 11 Version 23H2 for x64-based Systems.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 16,
        "ids": [
          "CVE-2026-33842",
          "CVE-2026-34328",
          "CVE-2026-34346",
          "CVE-2026-34348",
          "CVE-2026-40378",
          "CVE-2026-42982",
          "CVE-2026-42990",
          "CVE-2026-44800",
          "CVE-2026-48571",
          "CVE-2026-48572",
          "CVE-2026-49172",
          "CVE-2026-50471",
          "CVE-2026-56173",
          "CVE-2026-58601",
          "CVE-2026-58629",
          "CVE-2026-58640"
        ],
        "details": [
          {
            "id": "CVE-2026-33842",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39646,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-34328",
            "title": "Windows Audio Service Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39644,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-34346",
            "title": "Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability",
            "summary": "Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0027,
            "epssPercentile": 0.18916,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-34348",
            "title": "Windows Event Logging Service Information Disclosure Vulnerability",
            "summary": "Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00907,
            "epssPercentile": 0.57588,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-40378",
            "title": "Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability",
            "summary": "Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65473,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-42982",
            "title": "Windows Secure Kernel Mode Elevation of Privilege Vulnerability",
            "summary": "Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26114,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-42990",
            "title": "SQL Server ODBC driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59786,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-44800",
            "title": "Windows Push Notifications Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.1017,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48571",
            "title": "Windows App Package Installer Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18081,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48572",
            "title": "Windows App Package Installer Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10166,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49172",
            "title": "Windows FTP Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59785,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50471",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38793,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56173",
            "title": "Windows WebView Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18078,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58601",
            "title": "Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability",
            "summary": "Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26102,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58629",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.1808,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58640",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29001,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-49172",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-windows-kb5099535",
      "slug": "microsoft-2026-07-windows-kb5099535",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5099535",
      "title": "Deploy Microsoft Windows security update KB5099535",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5099535",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Windows 10 Version 1607 for 32-bit Systems, Windows 10 Version 1607 for x64-based Systems, Windows Server 2016, plus 1 more",
      "platform": "Windows",
      "release_version": "10.0.14393.9339",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 249 linked CVEs for Windows 10 Version 1607 for 32-bit Systems, Windows 10 Version 1607 for x64-based Systems, Windows Server 2016, plus 1 more. Microsoft reports exploitation for CVE-2026-56155.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 249,
        "ids": [
          "CVE-2026-33842",
          "CVE-2026-34346",
          "CVE-2026-40378",
          "CVE-2026-40400",
          "CVE-2026-40422",
          "CVE-2026-41087",
          "CVE-2026-42900",
          "CVE-2026-42975",
          "CVE-2026-42982",
          "CVE-2026-42990",
          "CVE-2026-44806",
          "CVE-2026-48564",
          "CVE-2026-49164",
          "CVE-2026-49165",
          "CVE-2026-49168",
          "CVE-2026-49171",
          "CVE-2026-49172",
          "CVE-2026-49176",
          "CVE-2026-49177",
          "CVE-2026-49178",
          "CVE-2026-49180",
          "CVE-2026-49181",
          "CVE-2026-49184",
          "CVE-2026-49783",
          "CVE-2026-49784",
          "CVE-2026-49787",
          "CVE-2026-49788",
          "CVE-2026-49789",
          "CVE-2026-49790",
          "CVE-2026-49791",
          "CVE-2026-49792",
          "CVE-2026-49793",
          "CVE-2026-49794",
          "CVE-2026-49796",
          "CVE-2026-49797",
          "CVE-2026-49798",
          "CVE-2026-49799",
          "CVE-2026-49801",
          "CVE-2026-49803",
          "CVE-2026-49804",
          "CVE-2026-49805",
          "CVE-2026-50294",
          "CVE-2026-50296",
          "CVE-2026-50297",
          "CVE-2026-50298",
          "CVE-2026-50299",
          "CVE-2026-50300",
          "CVE-2026-50304",
          "CVE-2026-50306",
          "CVE-2026-50308",
          "CVE-2026-50309",
          "CVE-2026-50311",
          "CVE-2026-50312",
          "CVE-2026-50313",
          "CVE-2026-50318",
          "CVE-2026-50321",
          "CVE-2026-50324",
          "CVE-2026-50325",
          "CVE-2026-50328",
          "CVE-2026-50330",
          "CVE-2026-50331",
          "CVE-2026-50332",
          "CVE-2026-50333",
          "CVE-2026-50334",
          "CVE-2026-50337",
          "CVE-2026-50341",
          "CVE-2026-50344",
          "CVE-2026-50346",
          "CVE-2026-50347",
          "CVE-2026-50351",
          "CVE-2026-50352",
          "CVE-2026-50354",
          "CVE-2026-50355",
          "CVE-2026-50356",
          "CVE-2026-50357",
          "CVE-2026-50358",
          "CVE-2026-50359",
          "CVE-2026-50362",
          "CVE-2026-50363",
          "CVE-2026-50365",
          "CVE-2026-50366",
          "CVE-2026-50368",
          "CVE-2026-50369",
          "CVE-2026-50370",
          "CVE-2026-50371",
          "CVE-2026-50372",
          "CVE-2026-50376",
          "CVE-2026-50377",
          "CVE-2026-50380",
          "CVE-2026-50386",
          "CVE-2026-50387",
          "CVE-2026-50388",
          "CVE-2026-50389",
          "CVE-2026-50390",
          "CVE-2026-50391",
          "CVE-2026-50394",
          "CVE-2026-50397",
          "CVE-2026-50400",
          "CVE-2026-50402",
          "CVE-2026-50405",
          "CVE-2026-50407",
          "CVE-2026-50409",
          "CVE-2026-50411",
          "CVE-2026-50412",
          "CVE-2026-50417",
          "CVE-2026-50419",
          "CVE-2026-50421",
          "CVE-2026-50422",
          "CVE-2026-50426",
          "CVE-2026-50429",
          "CVE-2026-50430",
          "CVE-2026-50431",
          "CVE-2026-50432",
          "CVE-2026-50433",
          "CVE-2026-50435",
          "CVE-2026-50437",
          "CVE-2026-50439",
          "CVE-2026-50441",
          "CVE-2026-50442",
          "CVE-2026-50444",
          "CVE-2026-50445",
          "CVE-2026-50447",
          "CVE-2026-50448",
          "CVE-2026-50451",
          "CVE-2026-50453",
          "CVE-2026-50455",
          "CVE-2026-50456",
          "CVE-2026-50461",
          "CVE-2026-50462",
          "CVE-2026-50470",
          "CVE-2026-50471",
          "CVE-2026-50473",
          "CVE-2026-50474",
          "CVE-2026-50475",
          "CVE-2026-50476",
          "CVE-2026-50477",
          "CVE-2026-50480",
          "CVE-2026-50482",
          "CVE-2026-50485",
          "CVE-2026-50489",
          "CVE-2026-50490",
          "CVE-2026-50491",
          "CVE-2026-50492",
          "CVE-2026-50494",
          "CVE-2026-50496",
          "CVE-2026-50497",
          "CVE-2026-50498",
          "CVE-2026-50500",
          "CVE-2026-50502",
          "CVE-2026-50504",
          "CVE-2026-50505",
          "CVE-2026-50509",
          "CVE-2026-50518",
          "CVE-2026-50647",
          "CVE-2026-50655",
          "CVE-2026-50661",
          "CVE-2026-50666",
          "CVE-2026-50667",
          "CVE-2026-50668",
          "CVE-2026-50669",
          "CVE-2026-50673",
          "CVE-2026-50681",
          "CVE-2026-50683",
          "CVE-2026-50684",
          "CVE-2026-50685",
          "CVE-2026-50686",
          "CVE-2026-50688",
          "CVE-2026-50690",
          "CVE-2026-50692",
          "CVE-2026-50694",
          "CVE-2026-50695",
          "CVE-2026-50697",
          "CVE-2026-54107",
          "CVE-2026-54109",
          "CVE-2026-54115",
          "CVE-2026-54119",
          "CVE-2026-54121",
          "CVE-2026-54122",
          "CVE-2026-54126",
          "CVE-2026-54128",
          "CVE-2026-54132",
          "CVE-2026-54982",
          "CVE-2026-54983",
          "CVE-2026-54986",
          "CVE-2026-54987",
          "CVE-2026-54989",
          "CVE-2026-54992",
          "CVE-2026-54995",
          "CVE-2026-54997",
          "CVE-2026-54999",
          "CVE-2026-55001",
          "CVE-2026-55003",
          "CVE-2026-55004",
          "CVE-2026-56155",
          "CVE-2026-56159",
          "CVE-2026-56175",
          "CVE-2026-56176",
          "CVE-2026-56182",
          "CVE-2026-56186",
          "CVE-2026-56188",
          "CVE-2026-56189",
          "CVE-2026-56190",
          "CVE-2026-56194",
          "CVE-2026-56643",
          "CVE-2026-56644",
          "CVE-2026-56647",
          "CVE-2026-56648",
          "CVE-2026-56649",
          "CVE-2026-56650",
          "CVE-2026-57083",
          "CVE-2026-57084",
          "CVE-2026-57085",
          "CVE-2026-57087",
          "CVE-2026-57089",
          "CVE-2026-57090",
          "CVE-2026-57091",
          "CVE-2026-57092",
          "CVE-2026-57093",
          "CVE-2026-57094",
          "CVE-2026-57095",
          "CVE-2026-57096",
          "CVE-2026-57097",
          "CVE-2026-57976",
          "CVE-2026-57979",
          "CVE-2026-57982",
          "CVE-2026-58530",
          "CVE-2026-58531",
          "CVE-2026-58532",
          "CVE-2026-58533",
          "CVE-2026-58534",
          "CVE-2026-58535",
          "CVE-2026-58539",
          "CVE-2026-58540",
          "CVE-2026-58541",
          "CVE-2026-58545",
          "CVE-2026-58546",
          "CVE-2026-58594",
          "CVE-2026-58601",
          "CVE-2026-58608",
          "CVE-2026-58609",
          "CVE-2026-58610",
          "CVE-2026-58614",
          "CVE-2026-58619",
          "CVE-2026-58627",
          "CVE-2026-58629",
          "CVE-2026-58632",
          "CVE-2026-58637",
          "CVE-2026-58638",
          "CVE-2026-58640"
        ],
        "details": [
          {
            "id": "CVE-2026-33842",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39646,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-34346",
            "title": "Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability",
            "summary": "Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0027,
            "epssPercentile": 0.18916,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-40378",
            "title": "Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability",
            "summary": "Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65473,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-40400",
            "title": "Windows PowerShell Remote Code Execution Vulnerability",
            "summary": "Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00868,
            "epssPercentile": 0.56393,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-40422",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33743,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-41087",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39643,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-42900",
            "title": "Microsoft Windows App Store Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00542,
            "epssPercentile": 0.43631,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-42975",
            "title": "Windows Bluetooth Port Driver Remote Code Execution",
            "summary": "Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00536,
            "epssPercentile": 0.43257,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-42982",
            "title": "Windows Secure Kernel Mode Elevation of Privilege Vulnerability",
            "summary": "Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26114,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-42990",
            "title": "SQL Server ODBC driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59786,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-44806",
            "title": "Windows Secure Channel Denial of Service Vulnerability",
            "summary": "Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65471,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48564",
            "title": "DHCP Server Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.5779,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49164",
            "title": "Windows Active Directory Domain Services Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53952,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49165",
            "title": "Microsoft Windows App Store Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00338,
            "epssPercentile": 0.26611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49168",
            "title": "Storage Spaces Direct Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36763,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49171",
            "title": "Windows Speech Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.003,
            "epssPercentile": 0.22345,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49172",
            "title": "Windows FTP Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59785,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49176",
            "title": "Windows WalletService Elevation of Privilege Vulnerability",
            "summary": "Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00471,
            "epssPercentile": 0.39116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49177",
            "title": "Windows TCP/IP Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00443,
            "epssPercentile": 0.37172,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49178",
            "title": "Windows Active Directory Domain Services Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.57789,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49180",
            "title": "Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00444,
            "epssPercentile": 0.37219,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49181",
            "title": "Windows DHCP Client Elevation of Privilege Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01172,
            "epssPercentile": 0.65406,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49184",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00337,
            "epssPercentile": 0.26479,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49783",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26114,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49784",
            "title": "Microsoft Windows App Store Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10169,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49787",
            "title": "HTTP.sys Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65471,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49788",
            "title": "HTTP/2 Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49789",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29002,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49790",
            "title": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
            "summary": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29001,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49791",
            "title": "Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0038,
            "epssPercentile": 0.31138,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49792",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26115,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49793",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26113,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49794",
            "title": "Windows USB Audio Class Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00468,
            "epssPercentile": 0.3893,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49796",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49797",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38802,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49798",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.",
            "score": 9.3,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00364,
            "epssPercentile": 0.29518,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49799",
            "title": "Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability",
            "summary": "Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01138,
            "epssPercentile": 0.64468,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49801",
            "title": "Windows SMB Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33744,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49803",
            "title": "Windows AppX Deployment Extensions Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.1017,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49804",
            "title": "Windows USB Video Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows USB Video Driver allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00483,
            "epssPercentile": 0.39895,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49805",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00236,
            "epssPercentile": 0.14488,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50294",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized attacker to disclose information locally.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00506,
            "epssPercentile": 0.41392,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50296",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Graphics Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18079,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50297",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00236,
            "epssPercentile": 0.14488,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50298",
            "title": "Windows Spaceport.sys Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36765,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50299",
            "title": "Windows Storage Spaces Direct Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36764,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50300",
            "title": "Windows DWM Core Library Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50304",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50306",
            "title": "Windows TCP/IP Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26104,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50308",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38802,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50309",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26104,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50311",
            "title": "Windows Server Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50312",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 4.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0035,
            "epssPercentile": 0.28037,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50313",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38794,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50318",
            "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26103,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50321",
            "title": "Windows USB Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11649,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50324",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00855,
            "epssPercentile": 0.5598,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50325",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00236,
            "epssPercentile": 0.14488,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50328",
            "title": "Windows Server Update Service (WSUS) Tampering Vulnerability",
            "summary": "Uncaught exception in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01232,
            "epssPercentile": 0.67,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50330",
            "title": "Windows Remote Desktop Client Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01252,
            "epssPercentile": 0.6748,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50331",
            "title": "Windows Application Model Core API Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Application Model allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50332",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50333",
            "title": "Windows Spaceport.sys Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50334",
            "title": "Windows Push Notification Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Notification allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39645,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50337",
            "title": "Windows Notification Elevation of Privilege Vulnerability",
            "summary": "Incorrect type conversion or cast in Windows Notification allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26104,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50341",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33741,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50344",
            "title": "Windows OLE Elevation of Privilege Vulnerability",
            "summary": "Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50346",
            "title": "Netlogon RPC Elevation of Privilege Vulnerability",
            "summary": "Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50347",
            "title": "Windows Data.dll Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38792,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50351",
            "title": "Windows Audio Compression Manager (ACM) Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50352",
            "title": "Windows Cryptographic Services Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50354",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26129,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50355",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50356",
            "title": "Microsoft Windows App Store Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10168,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50357",
            "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50358",
            "title": "Windows Media Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Media allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20051,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50359",
            "title": "Microsoft XML Core Services Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20051,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50362",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38801,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50363",
            "title": "Windows Push Notifications Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26102,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50365",
            "title": "Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability",
            "summary": "Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00542,
            "epssPercentile": 0.43604,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50366",
            "title": "Windows Active Directory Domain Services Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01138,
            "epssPercentile": 0.64468,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50368",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50369",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00701,
            "epssPercentile": 0.50891,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50370",
            "title": "DHCP Server Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00502,
            "epssPercentile": 0.41141,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50371",
            "title": "Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows LUAFV allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10167,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50372",
            "title": "Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability",
            "summary": "Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18081,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50376",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50377",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00409,
            "epssPercentile": 0.34158,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50380",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.",
            "score": 9.6,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.54859,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50386",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38791,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50387",
            "title": "Windows GDI Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26111,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50388",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38797,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50389",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39644,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50390",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20053,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50391",
            "title": "Windows Group Policy Elevation of Privilege Vulnerability",
            "summary": "Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.2211,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50394",
            "title": "Windows Media Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39643,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50397",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18081,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50400",
            "title": "Windows App Package Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.2611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50402",
            "title": "NTFS Elevation of Privilege Vulnerability",
            "summary": "Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.2611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50405",
            "title": "Windows Filtering Platform Elevation of Privilege Vulnerability",
            "summary": "Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50407",
            "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50409",
            "title": "Windows Overlay Filter Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Overlay Filter allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50411",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50412",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50417",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26111,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50419",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.",
            "score": 3.3,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00458,
            "epssPercentile": 0.38211,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50421",
            "title": "Windows Connected User Experiences and Telemetry Elevation of Privilege Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.2611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50422",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50426",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent network.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00558,
            "epssPercentile": 0.44441,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50429",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network.",
            "score": 8.2,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01069,
            "epssPercentile": 0.62606,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50430",
            "title": "Windows Push Notification Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39648,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50431",
            "title": "Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability",
            "summary": "Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39648,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50432",
            "title": "Window Virtual Filtering Platform (VFP) Denial of Service Vulnerability",
            "summary": "Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized attacker to deny service over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00953,
            "epssPercentile": 0.59049,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50433",
            "title": "Windows Media Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Media allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50435",
            "title": "Windows Overlay Filter Elevation of Privilege Vulnerability",
            "summary": "Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50437",
            "title": "Windows DWM Core Library Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50439",
            "title": "Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53953,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50441",
            "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
            "summary": "Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.2611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50442",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39646,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50444",
            "title": "Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00778,
            "epssPercentile": 0.53532,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50445",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58032,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50447",
            "title": "Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59787,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50448",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38799,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50451",
            "title": "Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00307,
            "epssPercentile": 0.23134,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50453",
            "title": "Windows USB Audio Class Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0051,
            "epssPercentile": 0.41673,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50455",
            "title": "Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33743,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50456",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39646,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50461",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38801,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50462",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00457,
            "epssPercentile": 0.38194,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50470",
            "title": "Windows Network Policy Server SNMP Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01027,
            "epssPercentile": 0.61358,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50471",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38793,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50473",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39644,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50474",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.54859,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50475",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.00375,
            "epssPercentile": 0.30678,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Medium technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50476",
            "title": "Windows Network Connections Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Windows allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20051,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50477",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.261,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50480",
            "title": "Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26097,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50482",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29001,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50485",
            "title": "Windows Hyper-V Denial of Service Vulnerability",
            "summary": "Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.",
            "score": 4.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00656,
            "epssPercentile": 0.49112,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50489",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50490",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20054,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50491",
            "title": "Code Integrity DLL (ci.dll) Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20054,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50492",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36764,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50494",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26098,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50496",
            "title": "Windows Network Policy Server SNMP Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50497",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58032,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50498",
            "title": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
            "summary": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00363,
            "epssPercentile": 0.29377,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50500",
            "title": "Windows Netlogon Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00742,
            "epssPercentile": 0.52348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50502",
            "title": "Windows Event Logging Service Remote Code Execution Vulnerability",
            "summary": "Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00654,
            "epssPercentile": 0.49042,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50504",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.5803,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50505",
            "title": "Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00742,
            "epssPercentile": 0.52348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50509",
            "title": "Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability",
            "summary": "Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0353,
            "epssPercentile": 0.88474,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50518",
            "title": "Windows DHCP Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59786,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50647",
            "title": "Active Directory Federation Server Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50655",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38797,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50661",
            "title": "Windows BitLocker Security Feature Bypass Vulnerability",
            "summary": "Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00481,
            "epssPercentile": 0.39822,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50666",
            "title": "Windows Remote Access Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.5779,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50667",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11651,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50668",
            "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36764,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50669",
            "title": "Windows Telephony Server Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.1017,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50673",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.1165,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50681",
            "title": "Windows Secure Channel Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39645,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50683",
            "title": "Windows DHCP Client Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00576,
            "epssPercentile": 0.45358,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50684",
            "title": "Active Directory Federation Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Active Directory Federation Services (AD FS) allows an authorized attacker to perform spoofing over a network.",
            "score": 4.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00395,
            "epssPercentile": 0.32825,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50685",
            "title": "Windows DHCP Server Remote Code Execution Vulnerability",
            "summary": "Double free in Windows DHCP Server allows an authorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00663,
            "epssPercentile": 0.49414,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50686",
            "title": "Windows OLE Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00707,
            "epssPercentile": 0.5113,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50688",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20053,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50690",
            "title": "Windows SMB Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50692",
            "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.261,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50694",
            "title": "Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53953,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50695",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65468,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50697",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00395,
            "epssPercentile": 0.32743,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54107",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11651,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54109",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54115",
            "title": "Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26115,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54119",
            "title": "Windows Active Directory Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54121",
            "title": "Active Directory Certificate Services Elevation of Privilege Vulnerability",
            "summary": "Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01788,
            "epssPercentile": 0.76867,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54122",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00364,
            "epssPercentile": 0.29518,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54126",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58034,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54128",
            "title": "Windows DHCP Client Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00364,
            "epssPercentile": 0.29519,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54132",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36764,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54982",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00535,
            "epssPercentile": 0.43236,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54983",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65471,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54986",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26113,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54987",
            "title": "Windows Overlay Filter Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54989",
            "title": "Quality Windows Audio/Video Experience (QWAVE) Elevation of Privilege Vulnerability",
            "summary": "Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20052,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54992",
            "title": "Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00337,
            "epssPercentile": 0.26479,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54995",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53953,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54997",
            "title": "Windows SMB Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54999",
            "title": "Windows TCP/IP Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0041,
            "epssPercentile": 0.34281,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55001",
            "title": "Active Directory Domain Services Elevation of Privilege Vulnerability",
            "summary": "Improper certificate validation in Windows Active Directory allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.2211,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55003",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55004",
            "title": "Windows Print Configuration Elevation of Privilege Vulnerability",
            "summary": "Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56155",
            "title": "Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability",
            "summary": "Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2026-07-14.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00346,
            "epssPercentile": 0.27582,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2026-07-28 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56159",
            "title": "DHCP Server Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59787,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56175",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26112,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56176",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26112,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56182",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26112,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56186",
            "title": "Windows Secure Channel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01106,
            "epssPercentile": 0.63644,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56188",
            "title": "Windows Server Network driver Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00607,
            "epssPercentile": 0.46852,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56189",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00393,
            "epssPercentile": 0.32499,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56190",
            "title": "Remote Desktop Protocol Remote Code Execution Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59787,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56194",
            "title": "Windows NFS Server Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.5779,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56643",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56644",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56647",
            "title": "Windows Remote Access Service Infrastructure Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.57789,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56648",
            "title": "Windows NFS Server Elevation of Privilege Vulnerability",
            "summary": "Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00509,
            "epssPercentile": 0.41581,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56649",
            "title": "Windows Network File System Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File System allows an unauthorized attacker to execute code over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00699,
            "epssPercentile": 0.50808,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56650",
            "title": "Windows Network File System Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57083",
            "title": "Windows Media Photo Codec Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.4355,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57084",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.43549,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57085",
            "title": "Windows Print Spooler Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0037,
            "epssPercentile": 0.30143,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57087",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53969,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57089",
            "title": "Windows SMB Server Network Transport Driver (srvnet.sys) Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00665,
            "epssPercentile": 0.49498,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57090",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.54858,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57091",
            "title": "Windows File History Service Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows File History Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57092",
            "title": "Microsoft Windows VMSwitch Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.",
            "score": 9.9,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.57791,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57093",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20053,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57094",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.54859,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57095",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00489,
            "epssPercentile": 0.40353,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57096",
            "title": "Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57097",
            "title": "Microsoft XML Security Feature Bypass Vulnerability",
            "summary": "Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack.",
            "score": 6.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00503,
            "epssPercentile": 0.41172,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57976",
            "title": "Windows Active Directory Domain Services Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01138,
            "epssPercentile": 0.64468,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57979",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58034,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57982",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00995,
            "epssPercentile": 0.60375,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58530",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00363,
            "epssPercentile": 0.29377,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58531",
            "title": "Windows SMB Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00509,
            "epssPercentile": 0.41581,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58532",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.261,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58533",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58033,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58534",
            "title": "Windows Input Method Editor (IME) Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26095,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58535",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58539",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58033,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58540",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58541",
            "title": "Microsoft DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26102,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58545",
            "title": "Windows Kernel Security Feature Bypass Vulnerability",
            "summary": "Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0035,
            "epssPercentile": 0.27951,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58546",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58033,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58594",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.5486,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58601",
            "title": "Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability",
            "summary": "Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26102,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58608",
            "title": "Windows Print Spooler Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00569,
            "epssPercentile": 0.45031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58609",
            "title": "Windows Graphics Component Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38794,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58610",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38797,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58614",
            "title": "Windows Kernel Security Feature Bypass Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33743,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58619",
            "title": "Windows Sensor Data Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.1808,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58627",
            "title": "Windows DHCP Server Denial of Service Vulnerability",
            "summary": "Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58629",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.1808,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58632",
            "title": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26101,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58637",
            "title": "Windows Client-Side Caching Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18082,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58638",
            "title": "Windows Boot Loader Security Feature Bypass Vulnerability",
            "summary": "Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.",
            "score": 6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00235,
            "epssPercentile": 0.14327,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58640",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29001,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Exploitation reported by the vendor source",
        "max_cvss": 9.9,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-57092",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-windows-kb5099536",
      "slug": "microsoft-2026-07-windows-kb5099536",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5099536",
      "title": "Deploy Microsoft Windows security update KB5099536",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5099536",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Windows Server 2025, Windows Server 2025 (Server Core installation)",
      "platform": "Windows",
      "release_version": "10.0.26100.33158",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 388 linked CVEs for Windows Server 2025, Windows Server 2025 (Server Core installation). Microsoft reports exploitation for CVE-2026-56155.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 388,
        "ids": [
          "CVE-2026-33842",
          "CVE-2026-34328",
          "CVE-2026-34346",
          "CVE-2026-34348",
          "CVE-2026-34349",
          "CVE-2026-40378",
          "CVE-2026-40400",
          "CVE-2026-40422",
          "CVE-2026-41087",
          "CVE-2026-42900",
          "CVE-2026-42975",
          "CVE-2026-42982",
          "CVE-2026-42990",
          "CVE-2026-44800",
          "CVE-2026-44806",
          "CVE-2026-48564",
          "CVE-2026-48571",
          "CVE-2026-48572",
          "CVE-2026-49162",
          "CVE-2026-49164",
          "CVE-2026-49165",
          "CVE-2026-49166",
          "CVE-2026-49167",
          "CVE-2026-49168",
          "CVE-2026-49169",
          "CVE-2026-49170",
          "CVE-2026-49171",
          "CVE-2026-49172",
          "CVE-2026-49174",
          "CVE-2026-49175",
          "CVE-2026-49176",
          "CVE-2026-49177",
          "CVE-2026-49178",
          "CVE-2026-49180",
          "CVE-2026-49181",
          "CVE-2026-49183",
          "CVE-2026-49184",
          "CVE-2026-49783",
          "CVE-2026-49784",
          "CVE-2026-49787",
          "CVE-2026-49788",
          "CVE-2026-49789",
          "CVE-2026-49790",
          "CVE-2026-49791",
          "CVE-2026-49792",
          "CVE-2026-49793",
          "CVE-2026-49794",
          "CVE-2026-49795",
          "CVE-2026-49796",
          "CVE-2026-49797",
          "CVE-2026-49798",
          "CVE-2026-49799",
          "CVE-2026-49800",
          "CVE-2026-49801",
          "CVE-2026-49802",
          "CVE-2026-49803",
          "CVE-2026-49804",
          "CVE-2026-49805",
          "CVE-2026-49806",
          "CVE-2026-49807",
          "CVE-2026-49808",
          "CVE-2026-50293",
          "CVE-2026-50294",
          "CVE-2026-50295",
          "CVE-2026-50296",
          "CVE-2026-50297",
          "CVE-2026-50298",
          "CVE-2026-50299",
          "CVE-2026-50300",
          "CVE-2026-50302",
          "CVE-2026-50303",
          "CVE-2026-50304",
          "CVE-2026-50305",
          "CVE-2026-50306",
          "CVE-2026-50307",
          "CVE-2026-50308",
          "CVE-2026-50309",
          "CVE-2026-50310",
          "CVE-2026-50311",
          "CVE-2026-50312",
          "CVE-2026-50313",
          "CVE-2026-50315",
          "CVE-2026-50316",
          "CVE-2026-50317",
          "CVE-2026-50318",
          "CVE-2026-50321",
          "CVE-2026-50322",
          "CVE-2026-50323",
          "CVE-2026-50324",
          "CVE-2026-50325",
          "CVE-2026-50326",
          "CVE-2026-50327",
          "CVE-2026-50328",
          "CVE-2026-50329",
          "CVE-2026-50330",
          "CVE-2026-50331",
          "CVE-2026-50332",
          "CVE-2026-50333",
          "CVE-2026-50334",
          "CVE-2026-50335",
          "CVE-2026-50337",
          "CVE-2026-50339",
          "CVE-2026-50340",
          "CVE-2026-50341",
          "CVE-2026-50343",
          "CVE-2026-50344",
          "CVE-2026-50345",
          "CVE-2026-50346",
          "CVE-2026-50347",
          "CVE-2026-50348",
          "CVE-2026-50350",
          "CVE-2026-50351",
          "CVE-2026-50352",
          "CVE-2026-50353",
          "CVE-2026-50354",
          "CVE-2026-50355",
          "CVE-2026-50356",
          "CVE-2026-50357",
          "CVE-2026-50358",
          "CVE-2026-50359",
          "CVE-2026-50360",
          "CVE-2026-50361",
          "CVE-2026-50362",
          "CVE-2026-50363",
          "CVE-2026-50365",
          "CVE-2026-50366",
          "CVE-2026-50367",
          "CVE-2026-50368",
          "CVE-2026-50369",
          "CVE-2026-50370",
          "CVE-2026-50371",
          "CVE-2026-50372",
          "CVE-2026-50373",
          "CVE-2026-50374",
          "CVE-2026-50375",
          "CVE-2026-50376",
          "CVE-2026-50377",
          "CVE-2026-50378",
          "CVE-2026-50380",
          "CVE-2026-50381",
          "CVE-2026-50382",
          "CVE-2026-50383",
          "CVE-2026-50384",
          "CVE-2026-50385",
          "CVE-2026-50386",
          "CVE-2026-50387",
          "CVE-2026-50388",
          "CVE-2026-50389",
          "CVE-2026-50390",
          "CVE-2026-50391",
          "CVE-2026-50392",
          "CVE-2026-50393",
          "CVE-2026-50394",
          "CVE-2026-50396",
          "CVE-2026-50397",
          "CVE-2026-50398",
          "CVE-2026-50399",
          "CVE-2026-50400",
          "CVE-2026-50401",
          "CVE-2026-50402",
          "CVE-2026-50403",
          "CVE-2026-50405",
          "CVE-2026-50407",
          "CVE-2026-50409",
          "CVE-2026-50410",
          "CVE-2026-50411",
          "CVE-2026-50412",
          "CVE-2026-50413",
          "CVE-2026-50414",
          "CVE-2026-50415",
          "CVE-2026-50416",
          "CVE-2026-50417",
          "CVE-2026-50418",
          "CVE-2026-50419",
          "CVE-2026-50420",
          "CVE-2026-50421",
          "CVE-2026-50422",
          "CVE-2026-50423",
          "CVE-2026-50424",
          "CVE-2026-50425",
          "CVE-2026-50426",
          "CVE-2026-50427",
          "CVE-2026-50429",
          "CVE-2026-50430",
          "CVE-2026-50431",
          "CVE-2026-50432",
          "CVE-2026-50433",
          "CVE-2026-50434",
          "CVE-2026-50435",
          "CVE-2026-50436",
          "CVE-2026-50437",
          "CVE-2026-50439",
          "CVE-2026-50441",
          "CVE-2026-50442",
          "CVE-2026-50444",
          "CVE-2026-50445",
          "CVE-2026-50447",
          "CVE-2026-50448",
          "CVE-2026-50449",
          "CVE-2026-50450",
          "CVE-2026-50451",
          "CVE-2026-50452",
          "CVE-2026-50453",
          "CVE-2026-50454",
          "CVE-2026-50455",
          "CVE-2026-50456",
          "CVE-2026-50457",
          "CVE-2026-50458",
          "CVE-2026-50459",
          "CVE-2026-50460",
          "CVE-2026-50461",
          "CVE-2026-50462",
          "CVE-2026-50463",
          "CVE-2026-50465",
          "CVE-2026-50466",
          "CVE-2026-50469",
          "CVE-2026-50470",
          "CVE-2026-50471",
          "CVE-2026-50473",
          "CVE-2026-50474",
          "CVE-2026-50475",
          "CVE-2026-50476",
          "CVE-2026-50477",
          "CVE-2026-50478",
          "CVE-2026-50479",
          "CVE-2026-50482",
          "CVE-2026-50483",
          "CVE-2026-50484",
          "CVE-2026-50485",
          "CVE-2026-50486",
          "CVE-2026-50487",
          "CVE-2026-50488",
          "CVE-2026-50489",
          "CVE-2026-50490",
          "CVE-2026-50491",
          "CVE-2026-50492",
          "CVE-2026-50493",
          "CVE-2026-50494",
          "CVE-2026-50495",
          "CVE-2026-50496",
          "CVE-2026-50497",
          "CVE-2026-50498",
          "CVE-2026-50499",
          "CVE-2026-50500",
          "CVE-2026-50501",
          "CVE-2026-50502",
          "CVE-2026-50503",
          "CVE-2026-50504",
          "CVE-2026-50505",
          "CVE-2026-50509",
          "CVE-2026-50518",
          "CVE-2026-50647",
          "CVE-2026-50655",
          "CVE-2026-50661",
          "CVE-2026-50666",
          "CVE-2026-50667",
          "CVE-2026-50668",
          "CVE-2026-50669",
          "CVE-2026-50670",
          "CVE-2026-50672",
          "CVE-2026-50673",
          "CVE-2026-50674",
          "CVE-2026-50679",
          "CVE-2026-50680",
          "CVE-2026-50681",
          "CVE-2026-50682",
          "CVE-2026-50683",
          "CVE-2026-50684",
          "CVE-2026-50685",
          "CVE-2026-50686",
          "CVE-2026-50687",
          "CVE-2026-50688",
          "CVE-2026-50689",
          "CVE-2026-50690",
          "CVE-2026-50692",
          "CVE-2026-50694",
          "CVE-2026-50695",
          "CVE-2026-50696",
          "CVE-2026-50697",
          "CVE-2026-54107",
          "CVE-2026-54109",
          "CVE-2026-54111",
          "CVE-2026-54112",
          "CVE-2026-54114",
          "CVE-2026-54115",
          "CVE-2026-54119",
          "CVE-2026-54121",
          "CVE-2026-54122",
          "CVE-2026-54124",
          "CVE-2026-54125",
          "CVE-2026-54126",
          "CVE-2026-54127",
          "CVE-2026-54128",
          "CVE-2026-54129",
          "CVE-2026-54982",
          "CVE-2026-54983",
          "CVE-2026-54986",
          "CVE-2026-54987",
          "CVE-2026-54989",
          "CVE-2026-54990",
          "CVE-2026-54991",
          "CVE-2026-54992",
          "CVE-2026-54993",
          "CVE-2026-54995",
          "CVE-2026-54996",
          "CVE-2026-54997",
          "CVE-2026-54999",
          "CVE-2026-55000",
          "CVE-2026-55001",
          "CVE-2026-55003",
          "CVE-2026-55004",
          "CVE-2026-55144",
          "CVE-2026-56155",
          "CVE-2026-56159",
          "CVE-2026-56168",
          "CVE-2026-56173",
          "CVE-2026-56175",
          "CVE-2026-56176",
          "CVE-2026-56181",
          "CVE-2026-56182",
          "CVE-2026-56184",
          "CVE-2026-56186",
          "CVE-2026-56188",
          "CVE-2026-56189",
          "CVE-2026-56190",
          "CVE-2026-56194",
          "CVE-2026-56643",
          "CVE-2026-56644",
          "CVE-2026-56647",
          "CVE-2026-56648",
          "CVE-2026-56649",
          "CVE-2026-56650",
          "CVE-2026-57083",
          "CVE-2026-57084",
          "CVE-2026-57085",
          "CVE-2026-57087",
          "CVE-2026-57088",
          "CVE-2026-57089",
          "CVE-2026-57090",
          "CVE-2026-57091",
          "CVE-2026-57092",
          "CVE-2026-57093",
          "CVE-2026-57094",
          "CVE-2026-57095",
          "CVE-2026-57096",
          "CVE-2026-57097",
          "CVE-2026-57976",
          "CVE-2026-57979",
          "CVE-2026-57982",
          "CVE-2026-58526",
          "CVE-2026-58527",
          "CVE-2026-58528",
          "CVE-2026-58530",
          "CVE-2026-58531",
          "CVE-2026-58532",
          "CVE-2026-58533",
          "CVE-2026-58534",
          "CVE-2026-58535",
          "CVE-2026-58536",
          "CVE-2026-58537",
          "CVE-2026-58538",
          "CVE-2026-58539",
          "CVE-2026-58540",
          "CVE-2026-58541",
          "CVE-2026-58542",
          "CVE-2026-58543",
          "CVE-2026-58544",
          "CVE-2026-58545",
          "CVE-2026-58546",
          "CVE-2026-58547",
          "CVE-2026-58594",
          "CVE-2026-58601",
          "CVE-2026-58602",
          "CVE-2026-58608",
          "CVE-2026-58609",
          "CVE-2026-58610",
          "CVE-2026-58613",
          "CVE-2026-58614",
          "CVE-2026-58619",
          "CVE-2026-58626",
          "CVE-2026-58627",
          "CVE-2026-58628",
          "CVE-2026-58629",
          "CVE-2026-58632",
          "CVE-2026-58635",
          "CVE-2026-58637",
          "CVE-2026-58638",
          "CVE-2026-58640"
        ],
        "details": [
          {
            "id": "CVE-2026-33842",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39646,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-34328",
            "title": "Windows Audio Service Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39644,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-34346",
            "title": "Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability",
            "summary": "Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0027,
            "epssPercentile": 0.18916,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-34348",
            "title": "Windows Event Logging Service Information Disclosure Vulnerability",
            "summary": "Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00907,
            "epssPercentile": 0.57588,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-34349",
            "title": "Windows Media Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39645,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-40378",
            "title": "Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability",
            "summary": "Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65473,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-40400",
            "title": "Windows PowerShell Remote Code Execution Vulnerability",
            "summary": "Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00868,
            "epssPercentile": 0.56393,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-40422",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33743,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-41087",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39643,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-42900",
            "title": "Microsoft Windows App Store Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00542,
            "epssPercentile": 0.43631,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-42975",
            "title": "Windows Bluetooth Port Driver Remote Code Execution",
            "summary": "Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00536,
            "epssPercentile": 0.43257,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-42982",
            "title": "Windows Secure Kernel Mode Elevation of Privilege Vulnerability",
            "summary": "Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26114,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-42990",
            "title": "SQL Server ODBC driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59786,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-44800",
            "title": "Windows Push Notifications Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.1017,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-44806",
            "title": "Windows Secure Channel Denial of Service Vulnerability",
            "summary": "Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65471,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48564",
            "title": "DHCP Server Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.5779,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48571",
            "title": "Windows App Package Installer Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18081,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48572",
            "title": "Windows App Package Installer Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10166,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49162",
            "title": "Microsoft Brokering File System Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18081,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49164",
            "title": "Windows Active Directory Domain Services Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53952,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49165",
            "title": "Microsoft Windows App Store Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00338,
            "epssPercentile": 0.26611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49166",
            "title": "Windows Print Configuration Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26113,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49167",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 4.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0035,
            "epssPercentile": 0.28037,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49168",
            "title": "Storage Spaces Direct Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36763,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49169",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Use after free in DNS Server allows an authorized attacker to execute code over a network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00753,
            "epssPercentile": 0.52715,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49170",
            "title": "Windows StateRepository API Server file Elevation of Privilege Vulnerability",
            "summary": "Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.2211,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49171",
            "title": "Windows Speech Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.003,
            "epssPercentile": 0.22345,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49172",
            "title": "Windows FTP Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59785,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49174",
            "title": "DNS Client Tampering Vulnerability",
            "summary": "Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0027,
            "epssPercentile": 0.18886,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49175",
            "title": "Windows DNS Client Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26114,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49176",
            "title": "Windows WalletService Elevation of Privilege Vulnerability",
            "summary": "Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00471,
            "epssPercentile": 0.39116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49177",
            "title": "Windows TCP/IP Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00443,
            "epssPercentile": 0.37172,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49178",
            "title": "Windows Active Directory Domain Services Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.57789,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49180",
            "title": "Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00444,
            "epssPercentile": 0.37219,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49181",
            "title": "Windows DHCP Client Elevation of Privilege Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01172,
            "epssPercentile": 0.65406,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49183",
            "title": "Windows Clipboard Server Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10168,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49184",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00337,
            "epssPercentile": 0.26479,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49783",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26114,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49784",
            "title": "Microsoft Windows App Store Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10169,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49787",
            "title": "HTTP.sys Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65471,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49788",
            "title": "HTTP/2 Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49789",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29002,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49790",
            "title": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
            "summary": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29001,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49791",
            "title": "Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0038,
            "epssPercentile": 0.31138,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49792",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26115,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49793",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26113,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49794",
            "title": "Windows USB Audio Class Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00468,
            "epssPercentile": 0.3893,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49795",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26115,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49796",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49797",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38802,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49798",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.",
            "score": 9.3,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00364,
            "epssPercentile": 0.29518,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49799",
            "title": "Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability",
            "summary": "Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01138,
            "epssPercentile": 0.64468,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49800",
            "title": "Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26115,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49801",
            "title": "Windows SMB Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33744,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49802",
            "title": "Windows USB Print Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10169,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49803",
            "title": "Windows AppX Deployment Extensions Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.1017,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49804",
            "title": "Windows USB Video Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows USB Video Driver allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00483,
            "epssPercentile": 0.39895,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49805",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00236,
            "epssPercentile": 0.14488,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49806",
            "title": "Windows USB Print Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10171,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49807",
            "title": "Windows DirectX Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows DirectX allows an unauthorized attacker to disclose information locally.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00506,
            "epssPercentile": 0.41392,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49808",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10167,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50293",
            "title": "Windows Internal Task Bar Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Internal Task Bar allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50294",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized attacker to disclose information locally.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00506,
            "epssPercentile": 0.41392,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50295",
            "title": "Windows Zero Trust DNS Security Feature Bypass Vulnerability",
            "summary": "Improper privilege management in Microsoft Windows DNS allows an authorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00302,
            "epssPercentile": 0.22534,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50296",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Graphics Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18079,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50297",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00236,
            "epssPercentile": 0.14488,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50298",
            "title": "Windows Spaceport.sys Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36765,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50299",
            "title": "Windows Storage Spaces Direct Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36764,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50300",
            "title": "Windows DWM Core Library Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50302",
            "title": "Windows Cryptographic Services Security Feature Bypass Vulnerability",
            "summary": "Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 4.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00334,
            "epssPercentile": 0.2625,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50303",
            "title": "Windows Key Guard Security Feature Bypass Vulnerability",
            "summary": "Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0027,
            "epssPercentile": 0.18916,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50304",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50305",
            "title": "Microsoft Brokering File System Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17026,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50306",
            "title": "Windows TCP/IP Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26104,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50307",
            "title": "Windows TCP/IP Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20052,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50308",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38802,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50309",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26104,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50310",
            "title": "Windows Human Interface Device Information Disclosure Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information locally.",
            "score": 4.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23556,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50311",
            "title": "Windows Server Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50312",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 4.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0035,
            "epssPercentile": 0.28037,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50313",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38794,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50315",
            "title": "Windows Image Acquisition Elevation of Privilege Vulnerability",
            "summary": "Null pointer dereference in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26103,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50316",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39648,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50317",
            "title": "Windows Operating Systems Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Operating Systems allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11648,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50318",
            "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26103,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50321",
            "title": "Windows USB Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11649,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50322",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10167,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50323",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18079,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50324",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00855,
            "epssPercentile": 0.5598,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50325",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00236,
            "epssPercentile": 0.14488,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50326",
            "title": "Windows Unified Consent System Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Unified Consent System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50327",
            "title": "Windows Media Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50328",
            "title": "Windows Server Update Service (WSUS) Tampering Vulnerability",
            "summary": "Uncaught exception in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01232,
            "epssPercentile": 0.67,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50329",
            "title": "Microsoft DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50330",
            "title": "Windows Remote Desktop Client Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01252,
            "epssPercentile": 0.6748,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50331",
            "title": "Windows Application Model Core API Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Application Model allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50332",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50333",
            "title": "Windows Spaceport.sys Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50334",
            "title": "Windows Push Notification Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Notification allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39645,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50335",
            "title": "Windows Operating Systems Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50337",
            "title": "Windows Notification Elevation of Privilege Vulnerability",
            "summary": "Incorrect type conversion or cast in Windows Notification allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26104,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50339",
            "title": "Windows Push Notification Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39645,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50340",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Runtime allows an authorized attacker to elevate privileges over a network.",
            "score": 8.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00742,
            "epssPercentile": 0.52348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50341",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33741,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50343",
            "title": "Microsoft Install Service Elevation of Privilege Vulnerability",
            "summary": "Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50344",
            "title": "Windows OLE Elevation of Privilege Vulnerability",
            "summary": "Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50345",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10168,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50346",
            "title": "Netlogon RPC Elevation of Privilege Vulnerability",
            "summary": "Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50347",
            "title": "Windows Data.dll Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38792,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50348",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0036,
            "epssPercentile": 0.29103,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50350",
            "title": "Windows Trusted Runtime Interface Driver Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39646,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50351",
            "title": "Windows Audio Compression Manager (ACM) Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50352",
            "title": "Windows Cryptographic Services Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50353",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50354",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26129,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50355",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50356",
            "title": "Microsoft Windows App Store Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10168,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50357",
            "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50358",
            "title": "Windows Media Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Media allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20051,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50359",
            "title": "Microsoft XML Core Services Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20051,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50360",
            "title": "Windows SMB Server Elevation of Privilege Vulnerability",
            "summary": "Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00778,
            "epssPercentile": 0.53532,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50361",
            "title": "Microsoft Brokering File System Elevation of Privilege Vulnerability",
            "summary": "Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17027,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50362",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38801,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50363",
            "title": "Windows Push Notifications Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26102,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50365",
            "title": "Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability",
            "summary": "Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00542,
            "epssPercentile": 0.43604,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50366",
            "title": "Windows Active Directory Domain Services Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01138,
            "epssPercentile": 0.64468,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50367",
            "title": "Windows Sensor Data Service Elevation of Privilege Vulnerability",
            "summary": "Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26103,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50368",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50369",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00701,
            "epssPercentile": 0.50891,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50370",
            "title": "DHCP Server Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00502,
            "epssPercentile": 0.41141,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50371",
            "title": "Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows LUAFV allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10167,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50372",
            "title": "Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability",
            "summary": "Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18081,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50373",
            "title": "Windows Search Service Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50374",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00347,
            "epssPercentile": 0.27656,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50375",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DirectX allows an authorized attacker to elevate privileges locally.",
            "score": 6.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00295,
            "epssPercentile": 0.21728,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50376",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50377",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00409,
            "epssPercentile": 0.34158,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50378",
            "title": "Windows Key Guard Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Key Guard allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11649,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50380",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.",
            "score": 9.6,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.54859,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50381",
            "title": "Composite Image File System driver (cimfs.sys) Information Disclosure Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Composite Image File System Driver allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33744,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50382",
            "title": "DirectX Graphics Kernel Remote Code Execution Vulnerability",
            "summary": "Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50383",
            "title": "Windows Print Spooler Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33741,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50384",
            "title": "Windows Clip Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clip Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10168,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50385",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17027,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50386",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38791,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50387",
            "title": "Windows GDI Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26111,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50388",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38797,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50389",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39644,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50390",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20053,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50391",
            "title": "Windows Group Policy Elevation of Privilege Vulnerability",
            "summary": "Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.2211,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50392",
            "title": "Windows Secure Kernel Mode Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18082,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50393",
            "title": "Windows Kernel-Mode Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20052,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50394",
            "title": "Windows Media Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39643,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50396",
            "title": "Windows Kernel-Mode Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20051,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50397",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18081,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50398",
            "title": "Windows Media Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00569,
            "epssPercentile": 0.4503,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50399",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26111,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50400",
            "title": "Windows App Package Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.2611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50401",
            "title": "Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33744,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50402",
            "title": "NTFS Elevation of Privilege Vulnerability",
            "summary": "Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.2611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50403",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10165,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50405",
            "title": "Windows Filtering Platform Elevation of Privilege Vulnerability",
            "summary": "Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50407",
            "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50409",
            "title": "Windows Overlay Filter Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Overlay Filter allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50410",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18079,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50411",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50412",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50413",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26098,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50414",
            "title": "Windows Media Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00569,
            "epssPercentile": 0.45031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50415",
            "title": "Windows Media Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Media allows an unauthorized attacker to disclose information over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0086,
            "epssPercentile": 0.56162,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50416",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 3.3,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00458,
            "epssPercentile": 0.38212,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50417",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26111,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50418",
            "title": "Windows System Secure Feature Bypass Vulnerability",
            "summary": "Improper access control in Windows System allows an unauthorized attacker to bypass a security feature locally.",
            "score": 5.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00266,
            "epssPercentile": 0.18272,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50419",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.",
            "score": 3.3,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00458,
            "epssPercentile": 0.38211,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50420",
            "title": "HTTP.sys Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to disclose information locally.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00408,
            "epssPercentile": 0.34085,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50421",
            "title": "Windows Connected User Experiences and Telemetry Elevation of Privilege Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.2611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50422",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50423",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50424",
            "title": "Windows Domain Controller Denial of Service Vulnerability",
            "summary": "Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65473,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50425",
            "title": "Windows Internal System User Profile Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Internal System User Profile allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50426",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent network.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00558,
            "epssPercentile": 0.44441,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50427",
            "title": "Content Delivery Manager Elevation of Privilege Vulnerability",
            "summary": "Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17026,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50429",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network.",
            "score": 8.2,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01069,
            "epssPercentile": 0.62606,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50430",
            "title": "Windows Push Notification Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39648,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50431",
            "title": "Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability",
            "summary": "Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39648,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50432",
            "title": "Window Virtual Filtering Platform (VFP) Denial of Service Vulnerability",
            "summary": "Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized attacker to deny service over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00953,
            "epssPercentile": 0.59049,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50433",
            "title": "Windows Media Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Media allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50434",
            "title": "Windows Push Notification Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50435",
            "title": "Windows Overlay Filter Elevation of Privilege Vulnerability",
            "summary": "Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50436",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50437",
            "title": "Windows DWM Core Library Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50439",
            "title": "Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53953,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50441",
            "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
            "summary": "Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.2611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50442",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39646,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50444",
            "title": "Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00778,
            "epssPercentile": 0.53532,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50445",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58032,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50447",
            "title": "Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59787,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50448",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38799,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50449",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18082,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50450",
            "title": "Windows Network Connections Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10166,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50451",
            "title": "Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00307,
            "epssPercentile": 0.23134,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50452",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0036,
            "epssPercentile": 0.29103,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50453",
            "title": "Windows USB Audio Class Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0051,
            "epssPercentile": 0.41673,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50454",
            "title": "Windows User Interface Core Elevation of Privilege Vulnerability",
            "summary": "Relative path traversal in Windows User Interface Core allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0037,
            "epssPercentile": 0.30148,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50455",
            "title": "Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33743,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50456",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39646,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50457",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17027,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50458",
            "title": "Microsoft Brokering File System Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17025,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50459",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22679,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50460",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00542,
            "epssPercentile": 0.4363,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50461",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38801,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50462",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00457,
            "epssPercentile": 0.38194,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50463",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01027,
            "epssPercentile": 0.61357,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50465",
            "title": "Windows DNS Client Tampering Vulnerability",
            "summary": "Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50466",
            "title": "Microsoft Brokering File System Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Brokering File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26096,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50469",
            "title": "Windows Projected File System Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows Projected File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0037,
            "epssPercentile": 0.30149,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50470",
            "title": "Windows Network Policy Server SNMP Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01027,
            "epssPercentile": 0.61358,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50471",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38793,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50473",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39644,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50474",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.54859,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50475",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.00375,
            "epssPercentile": 0.30678,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Medium technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50476",
            "title": "Windows Network Connections Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Windows allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20051,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50477",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.261,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50478",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26097,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50479",
            "title": "Windows USB Hub Driver Elevation of Privilege Vulnerability",
            "summary": "Untrusted pointer dereference in Windows USB Hub Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26097,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50482",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29001,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50483",
            "title": "Windows Graphics Component Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39643,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50484",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26112,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50485",
            "title": "Windows Hyper-V Denial of Service Vulnerability",
            "summary": "Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.",
            "score": 4.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00656,
            "epssPercentile": 0.49112,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50486",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26097,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50487",
            "title": "Windows DNS Client Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Windows DNS allows an unauthorized attacker to elevate privileges over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53953,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50488",
            "title": "Clipboard User Service Elevation of Privilege Vulnerability",
            "summary": "Improper neutralization of special elements used in a command ('command injection') in Windows Clipboard User Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00322,
            "epssPercentile": 0.24873,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50489",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50490",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20054,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50491",
            "title": "Code Integrity DLL (ci.dll) Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20054,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50492",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36764,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50493",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26098,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50494",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26098,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50495",
            "title": "DNS Client Tampering Vulnerability",
            "summary": "Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00302,
            "epssPercentile": 0.22534,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50496",
            "title": "Windows Network Policy Server SNMP Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50497",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58032,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50498",
            "title": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
            "summary": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00363,
            "epssPercentile": 0.29377,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50499",
            "title": "Windows Print Spooler Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50500",
            "title": "Windows Netlogon Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00742,
            "epssPercentile": 0.52348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50501",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00363,
            "epssPercentile": 0.29377,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50502",
            "title": "Windows Event Logging Service Remote Code Execution Vulnerability",
            "summary": "Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00654,
            "epssPercentile": 0.49042,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50503",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10169,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50504",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.5803,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50505",
            "title": "Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00742,
            "epssPercentile": 0.52348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50509",
            "title": "Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability",
            "summary": "Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0353,
            "epssPercentile": 0.88474,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50518",
            "title": "Windows DHCP Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59786,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50647",
            "title": "Active Directory Federation Server Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50655",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38797,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50661",
            "title": "Windows BitLocker Security Feature Bypass Vulnerability",
            "summary": "Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00481,
            "epssPercentile": 0.39822,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50666",
            "title": "Windows Remote Access Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.5779,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50667",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11651,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50668",
            "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36764,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50669",
            "title": "Windows Telephony Server Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.1017,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50670",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26096,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50672",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10166,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50673",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.1165,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50674",
            "title": "Windows USB Print Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.2005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50679",
            "title": "Windows Search Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26096,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50680",
            "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally.",
            "score": 8.2,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00338,
            "epssPercentile": 0.26665,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50681",
            "title": "Windows Secure Channel Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39645,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50682",
            "title": "Active Directory Denial of Service Vulnerability",
            "summary": "Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58293,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50683",
            "title": "Windows DHCP Client Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00576,
            "epssPercentile": 0.45358,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50684",
            "title": "Active Directory Federation Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Active Directory Federation Services (AD FS) allows an authorized attacker to perform spoofing over a network.",
            "score": 4.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00395,
            "epssPercentile": 0.32825,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50685",
            "title": "Windows DHCP Server Remote Code Execution Vulnerability",
            "summary": "Double free in Windows DHCP Server allows an authorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00663,
            "epssPercentile": 0.49414,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50686",
            "title": "Windows OLE Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00707,
            "epssPercentile": 0.5113,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50687",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26095,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50688",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20053,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50689",
            "title": "Windows Clipboard Server Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17026,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50690",
            "title": "Windows SMB Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50692",
            "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.261,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50694",
            "title": "Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53953,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50695",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65468,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50696",
            "title": "Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50697",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00395,
            "epssPercentile": 0.32743,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54107",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11651,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54109",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54111",
            "title": "Universal Print Management Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10165,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54112",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10171,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54114",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54115",
            "title": "Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26115,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54119",
            "title": "Windows Active Directory Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54121",
            "title": "Active Directory Certificate Services Elevation of Privilege Vulnerability",
            "summary": "Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01788,
            "epssPercentile": 0.76867,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54122",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00364,
            "epssPercentile": 0.29518,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54124",
            "title": "Windows Terminal Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.388,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54125",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17027,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54126",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58034,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54127",
            "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00305,
            "epssPercentile": 0.22804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54128",
            "title": "Windows DHCP Client Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00364,
            "epssPercentile": 0.29519,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54129",
            "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20054,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54982",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00535,
            "epssPercentile": 0.43236,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54983",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65471,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54986",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26113,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54987",
            "title": "Windows Overlay Filter Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54989",
            "title": "Quality Windows Audio/Video Experience (QWAVE) Elevation of Privilege Vulnerability",
            "summary": "Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20052,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54990",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.54861,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54991",
            "title": "Windows USB Print Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11649,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54992",
            "title": "Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00337,
            "epssPercentile": 0.26479,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54993",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38795,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54995",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53953,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54996",
            "title": "Windows USB Print Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10171,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54997",
            "title": "Windows SMB Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54999",
            "title": "Windows TCP/IP Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0041,
            "epssPercentile": 0.34281,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55000",
            "title": "Windows USB Print Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00339,
            "epssPercentile": 0.26781,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55001",
            "title": "Active Directory Domain Services Elevation of Privilege Vulnerability",
            "summary": "Improper certificate validation in Windows Active Directory allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.2211,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55003",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55004",
            "title": "Windows Print Configuration Elevation of Privilege Vulnerability",
            "summary": "Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55144",
            "title": "Windows Cryptography API: Next Generation (CNG) Tampering Vulnerability",
            "summary": "Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00225,
            "epssPercentile": 0.13158,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56155",
            "title": "Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability",
            "summary": "Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2026-07-14.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00346,
            "epssPercentile": 0.27582,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2026-07-28 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56159",
            "title": "DHCP Server Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59787,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56168",
            "title": "Windows SMB Server Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01138,
            "epssPercentile": 0.64469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56173",
            "title": "Windows WebView Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18078,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56175",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26112,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56176",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26112,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56181",
            "title": "Windows Network Address Translation (NAT) Spoofing Vulnerability",
            "summary": "Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.",
            "score": 8.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00276,
            "epssPercentile": 0.19734,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56182",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26112,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56184",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39643,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56186",
            "title": "Windows Secure Channel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01106,
            "epssPercentile": 0.63644,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56188",
            "title": "Windows Server Network driver Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00607,
            "epssPercentile": 0.46852,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56189",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00393,
            "epssPercentile": 0.32499,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56190",
            "title": "Remote Desktop Protocol Remote Code Execution Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59787,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56194",
            "title": "Windows NFS Server Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.5779,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56643",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56644",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56647",
            "title": "Windows Remote Access Service Infrastructure Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.57789,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56648",
            "title": "Windows NFS Server Elevation of Privilege Vulnerability",
            "summary": "Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00509,
            "epssPercentile": 0.41581,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56649",
            "title": "Windows Network File System Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File System allows an unauthorized attacker to execute code over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00699,
            "epssPercentile": 0.50808,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56650",
            "title": "Windows Network File System Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57083",
            "title": "Windows Media Photo Codec Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.4355,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57084",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.43549,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57085",
            "title": "Windows Print Spooler Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0037,
            "epssPercentile": 0.30143,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57087",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53969,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57088",
            "title": "Extensible Storage Engine (ESENT) Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57089",
            "title": "Windows SMB Server Network Transport Driver (srvnet.sys) Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00665,
            "epssPercentile": 0.49498,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57090",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.54858,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57091",
            "title": "Windows File History Service Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows File History Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57092",
            "title": "Microsoft Windows VMSwitch Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.",
            "score": 9.9,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.57791,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57093",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20053,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57094",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.54859,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57095",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00489,
            "epssPercentile": 0.40353,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57096",
            "title": "Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57097",
            "title": "Microsoft XML Security Feature Bypass Vulnerability",
            "summary": "Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack.",
            "score": 6.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00503,
            "epssPercentile": 0.41172,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57976",
            "title": "Windows Active Directory Domain Services Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01138,
            "epssPercentile": 0.64468,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57979",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58034,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57982",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00995,
            "epssPercentile": 0.60375,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58526",
            "title": "Windows Storage Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Storage allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11648,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58527",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.1165,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58528",
            "title": "Windows USB Audio Class Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00524,
            "epssPercentile": 0.42584,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58530",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00363,
            "epssPercentile": 0.29377,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58531",
            "title": "Windows SMB Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00509,
            "epssPercentile": 0.41581,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58532",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.261,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58533",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58033,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58534",
            "title": "Windows Input Method Editor (IME) Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26095,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58535",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58536",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26095,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58537",
            "title": "Microsoft NAT Helper Components (ipnathlp.dll) Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft NAT Helper Components (ipnathlp.dll) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.261,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58538",
            "title": "Windows Bluetooth Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26101,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58539",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58033,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58540",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58541",
            "title": "Microsoft DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26102,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58542",
            "title": "Windows Media Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00363,
            "epssPercentile": 0.29376,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58543",
            "title": "Universal Print Management Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00244,
            "epssPercentile": 0.15497,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58544",
            "title": "Windows Management Services Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.1808,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58545",
            "title": "Windows Kernel Security Feature Bypass Vulnerability",
            "summary": "Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0035,
            "epssPercentile": 0.27951,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58546",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58033,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58547",
            "title": "Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00407,
            "epssPercentile": 0.33974,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58594",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.5486,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58601",
            "title": "Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability",
            "summary": "Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26102,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58602",
            "title": "Windows Kernel-Mode Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26102,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58608",
            "title": "Windows Print Spooler Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00569,
            "epssPercentile": 0.45031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58609",
            "title": "Windows Graphics Component Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38794,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58610",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38797,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58613",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.00377,
            "epssPercentile": 0.30833,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58614",
            "title": "Windows Kernel Security Feature Bypass Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33743,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58619",
            "title": "Windows Sensor Data Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.1808,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58626",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.57789,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58627",
            "title": "Windows DHCP Server Denial of Service Vulnerability",
            "summary": "Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58628",
            "title": "Windows Wireless Network Manager Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10171,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58629",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.1808,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58632",
            "title": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26101,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58635",
            "title": "Windows Narrator Braille Elevation of Privilege Vulnerability",
            "summary": "Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00322,
            "epssPercentile": 0.24873,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58637",
            "title": "Windows Client-Side Caching Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18082,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58638",
            "title": "Windows Boot Loader Security Feature Bypass Vulnerability",
            "summary": "Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.",
            "score": 6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00235,
            "epssPercentile": 0.14327,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58640",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29001,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Exploitation reported by the vendor source",
        "max_cvss": 9.9,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-57092",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-windows-kb5099538",
      "slug": "microsoft-2026-07-windows-kb5099538",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5099538",
      "title": "Deploy Microsoft Windows security update KB5099538",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5099538",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, plus 1 more",
      "platform": "Windows",
      "release_version": "10.0.17763.9020",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 311 linked CVEs for Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, plus 1 more. Microsoft reports exploitation for CVE-2026-56155.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 311,
        "ids": [
          "CVE-2026-33842",
          "CVE-2026-34328",
          "CVE-2026-34346",
          "CVE-2026-34348",
          "CVE-2026-34349",
          "CVE-2026-40378",
          "CVE-2026-40400",
          "CVE-2026-40422",
          "CVE-2026-41087",
          "CVE-2026-42900",
          "CVE-2026-42975",
          "CVE-2026-42982",
          "CVE-2026-42990",
          "CVE-2026-44806",
          "CVE-2026-48564",
          "CVE-2026-49164",
          "CVE-2026-49165",
          "CVE-2026-49167",
          "CVE-2026-49168",
          "CVE-2026-49170",
          "CVE-2026-49171",
          "CVE-2026-49172",
          "CVE-2026-49174",
          "CVE-2026-49176",
          "CVE-2026-49177",
          "CVE-2026-49178",
          "CVE-2026-49180",
          "CVE-2026-49181",
          "CVE-2026-49183",
          "CVE-2026-49184",
          "CVE-2026-49783",
          "CVE-2026-49784",
          "CVE-2026-49787",
          "CVE-2026-49788",
          "CVE-2026-49789",
          "CVE-2026-49790",
          "CVE-2026-49791",
          "CVE-2026-49792",
          "CVE-2026-49793",
          "CVE-2026-49794",
          "CVE-2026-49795",
          "CVE-2026-49796",
          "CVE-2026-49797",
          "CVE-2026-49798",
          "CVE-2026-49799",
          "CVE-2026-49800",
          "CVE-2026-49801",
          "CVE-2026-49803",
          "CVE-2026-49804",
          "CVE-2026-49805",
          "CVE-2026-49807",
          "CVE-2026-50294",
          "CVE-2026-50296",
          "CVE-2026-50297",
          "CVE-2026-50298",
          "CVE-2026-50299",
          "CVE-2026-50300",
          "CVE-2026-50303",
          "CVE-2026-50304",
          "CVE-2026-50306",
          "CVE-2026-50307",
          "CVE-2026-50308",
          "CVE-2026-50309",
          "CVE-2026-50310",
          "CVE-2026-50311",
          "CVE-2026-50312",
          "CVE-2026-50313",
          "CVE-2026-50318",
          "CVE-2026-50321",
          "CVE-2026-50324",
          "CVE-2026-50325",
          "CVE-2026-50328",
          "CVE-2026-50329",
          "CVE-2026-50330",
          "CVE-2026-50331",
          "CVE-2026-50332",
          "CVE-2026-50333",
          "CVE-2026-50334",
          "CVE-2026-50335",
          "CVE-2026-50337",
          "CVE-2026-50339",
          "CVE-2026-50341",
          "CVE-2026-50343",
          "CVE-2026-50344",
          "CVE-2026-50346",
          "CVE-2026-50347",
          "CVE-2026-50348",
          "CVE-2026-50351",
          "CVE-2026-50352",
          "CVE-2026-50354",
          "CVE-2026-50355",
          "CVE-2026-50356",
          "CVE-2026-50357",
          "CVE-2026-50358",
          "CVE-2026-50359",
          "CVE-2026-50362",
          "CVE-2026-50363",
          "CVE-2026-50365",
          "CVE-2026-50366",
          "CVE-2026-50367",
          "CVE-2026-50368",
          "CVE-2026-50369",
          "CVE-2026-50370",
          "CVE-2026-50371",
          "CVE-2026-50372",
          "CVE-2026-50373",
          "CVE-2026-50374",
          "CVE-2026-50375",
          "CVE-2026-50376",
          "CVE-2026-50377",
          "CVE-2026-50378",
          "CVE-2026-50380",
          "CVE-2026-50382",
          "CVE-2026-50383",
          "CVE-2026-50384",
          "CVE-2026-50386",
          "CVE-2026-50387",
          "CVE-2026-50388",
          "CVE-2026-50389",
          "CVE-2026-50390",
          "CVE-2026-50391",
          "CVE-2026-50394",
          "CVE-2026-50397",
          "CVE-2026-50400",
          "CVE-2026-50401",
          "CVE-2026-50402",
          "CVE-2026-50405",
          "CVE-2026-50407",
          "CVE-2026-50409",
          "CVE-2026-50410",
          "CVE-2026-50411",
          "CVE-2026-50412",
          "CVE-2026-50415",
          "CVE-2026-50417",
          "CVE-2026-50419",
          "CVE-2026-50421",
          "CVE-2026-50422",
          "CVE-2026-50426",
          "CVE-2026-50427",
          "CVE-2026-50429",
          "CVE-2026-50430",
          "CVE-2026-50431",
          "CVE-2026-50432",
          "CVE-2026-50433",
          "CVE-2026-50435",
          "CVE-2026-50437",
          "CVE-2026-50439",
          "CVE-2026-50441",
          "CVE-2026-50442",
          "CVE-2026-50444",
          "CVE-2026-50445",
          "CVE-2026-50447",
          "CVE-2026-50448",
          "CVE-2026-50449",
          "CVE-2026-50450",
          "CVE-2026-50451",
          "CVE-2026-50452",
          "CVE-2026-50453",
          "CVE-2026-50455",
          "CVE-2026-50456",
          "CVE-2026-50457",
          "CVE-2026-50460",
          "CVE-2026-50461",
          "CVE-2026-50462",
          "CVE-2026-50463",
          "CVE-2026-50469",
          "CVE-2026-50470",
          "CVE-2026-50471",
          "CVE-2026-50473",
          "CVE-2026-50474",
          "CVE-2026-50475",
          "CVE-2026-50476",
          "CVE-2026-50477",
          "CVE-2026-50478",
          "CVE-2026-50479",
          "CVE-2026-50482",
          "CVE-2026-50484",
          "CVE-2026-50485",
          "CVE-2026-50489",
          "CVE-2026-50490",
          "CVE-2026-50491",
          "CVE-2026-50492",
          "CVE-2026-50493",
          "CVE-2026-50494",
          "CVE-2026-50495",
          "CVE-2026-50496",
          "CVE-2026-50497",
          "CVE-2026-50498",
          "CVE-2026-50499",
          "CVE-2026-50500",
          "CVE-2026-50502",
          "CVE-2026-50504",
          "CVE-2026-50505",
          "CVE-2026-50509",
          "CVE-2026-50518",
          "CVE-2026-50647",
          "CVE-2026-50655",
          "CVE-2026-50661",
          "CVE-2026-50666",
          "CVE-2026-50667",
          "CVE-2026-50668",
          "CVE-2026-50669",
          "CVE-2026-50670",
          "CVE-2026-50672",
          "CVE-2026-50673",
          "CVE-2026-50680",
          "CVE-2026-50681",
          "CVE-2026-50683",
          "CVE-2026-50684",
          "CVE-2026-50685",
          "CVE-2026-50686",
          "CVE-2026-50688",
          "CVE-2026-50689",
          "CVE-2026-50690",
          "CVE-2026-50692",
          "CVE-2026-50694",
          "CVE-2026-50695",
          "CVE-2026-50696",
          "CVE-2026-50697",
          "CVE-2026-54107",
          "CVE-2026-54109",
          "CVE-2026-54112",
          "CVE-2026-54114",
          "CVE-2026-54115",
          "CVE-2026-54119",
          "CVE-2026-54121",
          "CVE-2026-54122",
          "CVE-2026-54125",
          "CVE-2026-54126",
          "CVE-2026-54128",
          "CVE-2026-54129",
          "CVE-2026-54132",
          "CVE-2026-54982",
          "CVE-2026-54983",
          "CVE-2026-54986",
          "CVE-2026-54987",
          "CVE-2026-54989",
          "CVE-2026-54992",
          "CVE-2026-54993",
          "CVE-2026-54995",
          "CVE-2026-54997",
          "CVE-2026-54999",
          "CVE-2026-55001",
          "CVE-2026-55003",
          "CVE-2026-55004",
          "CVE-2026-56155",
          "CVE-2026-56159",
          "CVE-2026-56173",
          "CVE-2026-56175",
          "CVE-2026-56176",
          "CVE-2026-56182",
          "CVE-2026-56186",
          "CVE-2026-56188",
          "CVE-2026-56189",
          "CVE-2026-56190",
          "CVE-2026-56194",
          "CVE-2026-56643",
          "CVE-2026-56644",
          "CVE-2026-56647",
          "CVE-2026-56648",
          "CVE-2026-56649",
          "CVE-2026-56650",
          "CVE-2026-57083",
          "CVE-2026-57084",
          "CVE-2026-57085",
          "CVE-2026-57087",
          "CVE-2026-57088",
          "CVE-2026-57089",
          "CVE-2026-57090",
          "CVE-2026-57091",
          "CVE-2026-57092",
          "CVE-2026-57093",
          "CVE-2026-57094",
          "CVE-2026-57095",
          "CVE-2026-57096",
          "CVE-2026-57097",
          "CVE-2026-57976",
          "CVE-2026-57979",
          "CVE-2026-57982",
          "CVE-2026-58526",
          "CVE-2026-58528",
          "CVE-2026-58530",
          "CVE-2026-58531",
          "CVE-2026-58532",
          "CVE-2026-58533",
          "CVE-2026-58534",
          "CVE-2026-58535",
          "CVE-2026-58536",
          "CVE-2026-58538",
          "CVE-2026-58539",
          "CVE-2026-58540",
          "CVE-2026-58541",
          "CVE-2026-58545",
          "CVE-2026-58546",
          "CVE-2026-58547",
          "CVE-2026-58594",
          "CVE-2026-58601",
          "CVE-2026-58608",
          "CVE-2026-58609",
          "CVE-2026-58610",
          "CVE-2026-58613",
          "CVE-2026-58614",
          "CVE-2026-58619",
          "CVE-2026-58627",
          "CVE-2026-58628",
          "CVE-2026-58629",
          "CVE-2026-58632",
          "CVE-2026-58635",
          "CVE-2026-58637",
          "CVE-2026-58638",
          "CVE-2026-58640"
        ],
        "details": [
          {
            "id": "CVE-2026-33842",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39646,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-34328",
            "title": "Windows Audio Service Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39644,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-34346",
            "title": "Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability",
            "summary": "Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0027,
            "epssPercentile": 0.18916,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-34348",
            "title": "Windows Event Logging Service Information Disclosure Vulnerability",
            "summary": "Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00907,
            "epssPercentile": 0.57588,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-34349",
            "title": "Windows Media Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39645,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-40378",
            "title": "Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability",
            "summary": "Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65473,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-40400",
            "title": "Windows PowerShell Remote Code Execution Vulnerability",
            "summary": "Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00868,
            "epssPercentile": 0.56393,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-40422",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33743,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-41087",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39643,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-42900",
            "title": "Microsoft Windows App Store Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00542,
            "epssPercentile": 0.43631,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-42975",
            "title": "Windows Bluetooth Port Driver Remote Code Execution",
            "summary": "Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00536,
            "epssPercentile": 0.43257,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-42982",
            "title": "Windows Secure Kernel Mode Elevation of Privilege Vulnerability",
            "summary": "Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26114,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-42990",
            "title": "SQL Server ODBC driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59786,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-44806",
            "title": "Windows Secure Channel Denial of Service Vulnerability",
            "summary": "Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65471,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48564",
            "title": "DHCP Server Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.5779,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49164",
            "title": "Windows Active Directory Domain Services Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53952,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49165",
            "title": "Microsoft Windows App Store Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00338,
            "epssPercentile": 0.26611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49167",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 4.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0035,
            "epssPercentile": 0.28037,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49168",
            "title": "Storage Spaces Direct Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36763,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49170",
            "title": "Windows StateRepository API Server file Elevation of Privilege Vulnerability",
            "summary": "Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.2211,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49171",
            "title": "Windows Speech Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.003,
            "epssPercentile": 0.22345,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49172",
            "title": "Windows FTP Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59785,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49174",
            "title": "DNS Client Tampering Vulnerability",
            "summary": "Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0027,
            "epssPercentile": 0.18886,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49176",
            "title": "Windows WalletService Elevation of Privilege Vulnerability",
            "summary": "Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00471,
            "epssPercentile": 0.39116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49177",
            "title": "Windows TCP/IP Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00443,
            "epssPercentile": 0.37172,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49178",
            "title": "Windows Active Directory Domain Services Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.57789,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49180",
            "title": "Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00444,
            "epssPercentile": 0.37219,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49181",
            "title": "Windows DHCP Client Elevation of Privilege Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01172,
            "epssPercentile": 0.65406,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49183",
            "title": "Windows Clipboard Server Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10168,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49184",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00337,
            "epssPercentile": 0.26479,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49783",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26114,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49784",
            "title": "Microsoft Windows App Store Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10169,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49787",
            "title": "HTTP.sys Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65471,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49788",
            "title": "HTTP/2 Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49789",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29002,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49790",
            "title": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
            "summary": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29001,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49791",
            "title": "Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0038,
            "epssPercentile": 0.31138,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49792",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26115,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49793",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26113,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49794",
            "title": "Windows USB Audio Class Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00468,
            "epssPercentile": 0.3893,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49795",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26115,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49796",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49797",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38802,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49798",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.",
            "score": 9.3,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00364,
            "epssPercentile": 0.29518,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49799",
            "title": "Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability",
            "summary": "Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01138,
            "epssPercentile": 0.64468,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49800",
            "title": "Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26115,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49801",
            "title": "Windows SMB Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33744,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49803",
            "title": "Windows AppX Deployment Extensions Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.1017,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49804",
            "title": "Windows USB Video Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows USB Video Driver allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00483,
            "epssPercentile": 0.39895,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49805",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00236,
            "epssPercentile": 0.14488,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49807",
            "title": "Windows DirectX Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows DirectX allows an unauthorized attacker to disclose information locally.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00506,
            "epssPercentile": 0.41392,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50294",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized attacker to disclose information locally.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00506,
            "epssPercentile": 0.41392,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50296",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Graphics Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18079,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50297",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00236,
            "epssPercentile": 0.14488,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50298",
            "title": "Windows Spaceport.sys Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36765,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50299",
            "title": "Windows Storage Spaces Direct Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36764,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50300",
            "title": "Windows DWM Core Library Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50303",
            "title": "Windows Key Guard Security Feature Bypass Vulnerability",
            "summary": "Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0027,
            "epssPercentile": 0.18916,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50304",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50306",
            "title": "Windows TCP/IP Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26104,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50307",
            "title": "Windows TCP/IP Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20052,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50308",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38802,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50309",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26104,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50310",
            "title": "Windows Human Interface Device Information Disclosure Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information locally.",
            "score": 4.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23556,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50311",
            "title": "Windows Server Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50312",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 4.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0035,
            "epssPercentile": 0.28037,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50313",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38794,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50318",
            "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26103,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50321",
            "title": "Windows USB Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11649,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50324",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00855,
            "epssPercentile": 0.5598,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50325",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00236,
            "epssPercentile": 0.14488,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50328",
            "title": "Windows Server Update Service (WSUS) Tampering Vulnerability",
            "summary": "Uncaught exception in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01232,
            "epssPercentile": 0.67,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50329",
            "title": "Microsoft DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50330",
            "title": "Windows Remote Desktop Client Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01252,
            "epssPercentile": 0.6748,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50331",
            "title": "Windows Application Model Core API Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Application Model allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50332",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50333",
            "title": "Windows Spaceport.sys Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50334",
            "title": "Windows Push Notification Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Notification allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39645,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50335",
            "title": "Windows Operating Systems Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50337",
            "title": "Windows Notification Elevation of Privilege Vulnerability",
            "summary": "Incorrect type conversion or cast in Windows Notification allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26104,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50339",
            "title": "Windows Push Notification Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39645,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50341",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33741,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50343",
            "title": "Microsoft Install Service Elevation of Privilege Vulnerability",
            "summary": "Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50344",
            "title": "Windows OLE Elevation of Privilege Vulnerability",
            "summary": "Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50346",
            "title": "Netlogon RPC Elevation of Privilege Vulnerability",
            "summary": "Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50347",
            "title": "Windows Data.dll Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38792,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50348",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0036,
            "epssPercentile": 0.29103,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50351",
            "title": "Windows Audio Compression Manager (ACM) Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50352",
            "title": "Windows Cryptographic Services Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50354",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26129,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50355",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50356",
            "title": "Microsoft Windows App Store Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10168,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50357",
            "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50358",
            "title": "Windows Media Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Media allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20051,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50359",
            "title": "Microsoft XML Core Services Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20051,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50362",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38801,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50363",
            "title": "Windows Push Notifications Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26102,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50365",
            "title": "Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability",
            "summary": "Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00542,
            "epssPercentile": 0.43604,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50366",
            "title": "Windows Active Directory Domain Services Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01138,
            "epssPercentile": 0.64468,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50367",
            "title": "Windows Sensor Data Service Elevation of Privilege Vulnerability",
            "summary": "Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26103,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50368",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50369",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00701,
            "epssPercentile": 0.50891,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50370",
            "title": "DHCP Server Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00502,
            "epssPercentile": 0.41141,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50371",
            "title": "Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows LUAFV allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10167,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50372",
            "title": "Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability",
            "summary": "Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18081,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50373",
            "title": "Windows Search Service Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50374",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00347,
            "epssPercentile": 0.27656,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50375",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DirectX allows an authorized attacker to elevate privileges locally.",
            "score": 6.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00295,
            "epssPercentile": 0.21728,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50376",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50377",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00409,
            "epssPercentile": 0.34158,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50378",
            "title": "Windows Key Guard Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Key Guard allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11649,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50380",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.",
            "score": 9.6,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.54859,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50382",
            "title": "DirectX Graphics Kernel Remote Code Execution Vulnerability",
            "summary": "Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50383",
            "title": "Windows Print Spooler Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33741,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50384",
            "title": "Windows Clip Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clip Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10168,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50386",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38791,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50387",
            "title": "Windows GDI Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26111,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50388",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38797,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50389",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39644,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50390",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20053,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50391",
            "title": "Windows Group Policy Elevation of Privilege Vulnerability",
            "summary": "Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.2211,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50394",
            "title": "Windows Media Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39643,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50397",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18081,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50400",
            "title": "Windows App Package Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.2611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50401",
            "title": "Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33744,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50402",
            "title": "NTFS Elevation of Privilege Vulnerability",
            "summary": "Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.2611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50405",
            "title": "Windows Filtering Platform Elevation of Privilege Vulnerability",
            "summary": "Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50407",
            "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50409",
            "title": "Windows Overlay Filter Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Overlay Filter allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50410",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18079,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50411",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50412",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50415",
            "title": "Windows Media Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Media allows an unauthorized attacker to disclose information over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0086,
            "epssPercentile": 0.56162,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50417",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26111,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50419",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.",
            "score": 3.3,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00458,
            "epssPercentile": 0.38211,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50421",
            "title": "Windows Connected User Experiences and Telemetry Elevation of Privilege Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.2611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50422",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50426",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent network.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00558,
            "epssPercentile": 0.44441,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50427",
            "title": "Content Delivery Manager Elevation of Privilege Vulnerability",
            "summary": "Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17026,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50429",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network.",
            "score": 8.2,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01069,
            "epssPercentile": 0.62606,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50430",
            "title": "Windows Push Notification Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39648,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50431",
            "title": "Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability",
            "summary": "Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39648,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50432",
            "title": "Window Virtual Filtering Platform (VFP) Denial of Service Vulnerability",
            "summary": "Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized attacker to deny service over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00953,
            "epssPercentile": 0.59049,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50433",
            "title": "Windows Media Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Media allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50435",
            "title": "Windows Overlay Filter Elevation of Privilege Vulnerability",
            "summary": "Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50437",
            "title": "Windows DWM Core Library Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50439",
            "title": "Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53953,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50441",
            "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
            "summary": "Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.2611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50442",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39646,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50444",
            "title": "Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00778,
            "epssPercentile": 0.53532,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50445",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58032,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50447",
            "title": "Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59787,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50448",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38799,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50449",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18082,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50450",
            "title": "Windows Network Connections Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10166,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50451",
            "title": "Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00307,
            "epssPercentile": 0.23134,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50452",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0036,
            "epssPercentile": 0.29103,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50453",
            "title": "Windows USB Audio Class Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0051,
            "epssPercentile": 0.41673,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50455",
            "title": "Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33743,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50456",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39646,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50457",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17027,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50460",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00542,
            "epssPercentile": 0.4363,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50461",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38801,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50462",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00457,
            "epssPercentile": 0.38194,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50463",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01027,
            "epssPercentile": 0.61357,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50469",
            "title": "Windows Projected File System Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows Projected File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0037,
            "epssPercentile": 0.30149,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50470",
            "title": "Windows Network Policy Server SNMP Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01027,
            "epssPercentile": 0.61358,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50471",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38793,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50473",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39644,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50474",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.54859,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50475",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.00375,
            "epssPercentile": 0.30678,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Medium technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50476",
            "title": "Windows Network Connections Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Windows allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20051,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50477",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.261,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50478",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26097,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50479",
            "title": "Windows USB Hub Driver Elevation of Privilege Vulnerability",
            "summary": "Untrusted pointer dereference in Windows USB Hub Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26097,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50482",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29001,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50484",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26112,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50485",
            "title": "Windows Hyper-V Denial of Service Vulnerability",
            "summary": "Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.",
            "score": 4.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00656,
            "epssPercentile": 0.49112,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50489",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50490",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20054,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50491",
            "title": "Code Integrity DLL (ci.dll) Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20054,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50492",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36764,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50493",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26098,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50494",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26098,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50495",
            "title": "DNS Client Tampering Vulnerability",
            "summary": "Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00302,
            "epssPercentile": 0.22534,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50496",
            "title": "Windows Network Policy Server SNMP Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50497",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58032,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50498",
            "title": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
            "summary": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00363,
            "epssPercentile": 0.29377,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50499",
            "title": "Windows Print Spooler Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50500",
            "title": "Windows Netlogon Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00742,
            "epssPercentile": 0.52348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50502",
            "title": "Windows Event Logging Service Remote Code Execution Vulnerability",
            "summary": "Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00654,
            "epssPercentile": 0.49042,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50504",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.5803,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50505",
            "title": "Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00742,
            "epssPercentile": 0.52348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50509",
            "title": "Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability",
            "summary": "Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0353,
            "epssPercentile": 0.88474,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50518",
            "title": "Windows DHCP Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59786,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50647",
            "title": "Active Directory Federation Server Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50655",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38797,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50661",
            "title": "Windows BitLocker Security Feature Bypass Vulnerability",
            "summary": "Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00481,
            "epssPercentile": 0.39822,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50666",
            "title": "Windows Remote Access Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.5779,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50667",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11651,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50668",
            "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36764,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50669",
            "title": "Windows Telephony Server Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.1017,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50670",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26096,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50672",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10166,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50673",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.1165,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50680",
            "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally.",
            "score": 8.2,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00338,
            "epssPercentile": 0.26665,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50681",
            "title": "Windows Secure Channel Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39645,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50683",
            "title": "Windows DHCP Client Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00576,
            "epssPercentile": 0.45358,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50684",
            "title": "Active Directory Federation Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Active Directory Federation Services (AD FS) allows an authorized attacker to perform spoofing over a network.",
            "score": 4.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00395,
            "epssPercentile": 0.32825,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50685",
            "title": "Windows DHCP Server Remote Code Execution Vulnerability",
            "summary": "Double free in Windows DHCP Server allows an authorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00663,
            "epssPercentile": 0.49414,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50686",
            "title": "Windows OLE Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00707,
            "epssPercentile": 0.5113,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50688",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20053,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50689",
            "title": "Windows Clipboard Server Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17026,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50690",
            "title": "Windows SMB Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50692",
            "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.261,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50694",
            "title": "Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53953,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50695",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65468,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50696",
            "title": "Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50697",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00395,
            "epssPercentile": 0.32743,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54107",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11651,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54109",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54112",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10171,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54114",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54115",
            "title": "Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26115,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54119",
            "title": "Windows Active Directory Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54121",
            "title": "Active Directory Certificate Services Elevation of Privilege Vulnerability",
            "summary": "Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01788,
            "epssPercentile": 0.76867,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54122",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00364,
            "epssPercentile": 0.29518,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54125",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17027,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54126",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58034,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54128",
            "title": "Windows DHCP Client Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00364,
            "epssPercentile": 0.29519,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54129",
            "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20054,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54132",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36764,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54982",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00535,
            "epssPercentile": 0.43236,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54983",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65471,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54986",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26113,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54987",
            "title": "Windows Overlay Filter Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54989",
            "title": "Quality Windows Audio/Video Experience (QWAVE) Elevation of Privilege Vulnerability",
            "summary": "Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20052,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54992",
            "title": "Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00337,
            "epssPercentile": 0.26479,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54993",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38795,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54995",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53953,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54997",
            "title": "Windows SMB Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54999",
            "title": "Windows TCP/IP Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0041,
            "epssPercentile": 0.34281,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55001",
            "title": "Active Directory Domain Services Elevation of Privilege Vulnerability",
            "summary": "Improper certificate validation in Windows Active Directory allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.2211,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55003",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55004",
            "title": "Windows Print Configuration Elevation of Privilege Vulnerability",
            "summary": "Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56155",
            "title": "Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability",
            "summary": "Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2026-07-14.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00346,
            "epssPercentile": 0.27582,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2026-07-28 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56159",
            "title": "DHCP Server Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59787,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56173",
            "title": "Windows WebView Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18078,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56175",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26112,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56176",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26112,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56182",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26112,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56186",
            "title": "Windows Secure Channel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01106,
            "epssPercentile": 0.63644,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56188",
            "title": "Windows Server Network driver Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00607,
            "epssPercentile": 0.46852,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56189",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00393,
            "epssPercentile": 0.32499,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56190",
            "title": "Remote Desktop Protocol Remote Code Execution Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59787,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56194",
            "title": "Windows NFS Server Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.5779,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56643",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56644",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56647",
            "title": "Windows Remote Access Service Infrastructure Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.57789,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56648",
            "title": "Windows NFS Server Elevation of Privilege Vulnerability",
            "summary": "Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00509,
            "epssPercentile": 0.41581,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56649",
            "title": "Windows Network File System Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File System allows an unauthorized attacker to execute code over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00699,
            "epssPercentile": 0.50808,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56650",
            "title": "Windows Network File System Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57083",
            "title": "Windows Media Photo Codec Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.4355,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57084",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.43549,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57085",
            "title": "Windows Print Spooler Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0037,
            "epssPercentile": 0.30143,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57087",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53969,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57088",
            "title": "Extensible Storage Engine (ESENT) Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57089",
            "title": "Windows SMB Server Network Transport Driver (srvnet.sys) Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00665,
            "epssPercentile": 0.49498,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57090",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.54858,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57091",
            "title": "Windows File History Service Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows File History Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57092",
            "title": "Microsoft Windows VMSwitch Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.",
            "score": 9.9,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.57791,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57093",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20053,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57094",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.54859,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57095",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00489,
            "epssPercentile": 0.40353,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57096",
            "title": "Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57097",
            "title": "Microsoft XML Security Feature Bypass Vulnerability",
            "summary": "Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack.",
            "score": 6.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00503,
            "epssPercentile": 0.41172,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57976",
            "title": "Windows Active Directory Domain Services Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01138,
            "epssPercentile": 0.64468,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57979",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58034,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57982",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00995,
            "epssPercentile": 0.60375,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58526",
            "title": "Windows Storage Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Storage allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11648,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58528",
            "title": "Windows USB Audio Class Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00524,
            "epssPercentile": 0.42584,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58530",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00363,
            "epssPercentile": 0.29377,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58531",
            "title": "Windows SMB Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00509,
            "epssPercentile": 0.41581,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58532",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.261,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58533",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58033,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58534",
            "title": "Windows Input Method Editor (IME) Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26095,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58535",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58536",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26095,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58538",
            "title": "Windows Bluetooth Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26101,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58539",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58033,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58540",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58541",
            "title": "Microsoft DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26102,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58545",
            "title": "Windows Kernel Security Feature Bypass Vulnerability",
            "summary": "Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0035,
            "epssPercentile": 0.27951,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58546",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58033,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58547",
            "title": "Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00407,
            "epssPercentile": 0.33974,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58594",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.5486,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58601",
            "title": "Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability",
            "summary": "Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26102,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58608",
            "title": "Windows Print Spooler Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00569,
            "epssPercentile": 0.45031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58609",
            "title": "Windows Graphics Component Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38794,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58610",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38797,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58613",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.00377,
            "epssPercentile": 0.30833,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58614",
            "title": "Windows Kernel Security Feature Bypass Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33743,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58619",
            "title": "Windows Sensor Data Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.1808,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58627",
            "title": "Windows DHCP Server Denial of Service Vulnerability",
            "summary": "Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58628",
            "title": "Windows Wireless Network Manager Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10171,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58629",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.1808,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58632",
            "title": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26101,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58635",
            "title": "Windows Narrator Braille Elevation of Privilege Vulnerability",
            "summary": "Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00322,
            "epssPercentile": 0.24873,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58637",
            "title": "Windows Client-Side Caching Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18082,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58638",
            "title": "Windows Boot Loader Security Feature Bypass Vulnerability",
            "summary": "Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.",
            "score": 6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00235,
            "epssPercentile": 0.14327,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58640",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29001,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Exploitation reported by the vendor source",
        "max_cvss": 9.9,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-57092",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-windows-kb5099539",
      "slug": "microsoft-2026-07-windows-kb5099539",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5099539",
      "title": "Deploy Microsoft Windows security update KB5099539",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5099539",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems",
      "platform": "Windows",
      "release_version": "10.0.19044.7548",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 312 linked CVEs for Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems. Microsoft marks CVE-2026-50661 as publicly disclosed, without that disclosure alone changing the BlackTree action window.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 312,
        "ids": [
          "CVE-2026-33842",
          "CVE-2026-34328",
          "CVE-2026-34346",
          "CVE-2026-34348",
          "CVE-2026-34349",
          "CVE-2026-40378",
          "CVE-2026-40400",
          "CVE-2026-40422",
          "CVE-2026-41087",
          "CVE-2026-42900",
          "CVE-2026-42975",
          "CVE-2026-42982",
          "CVE-2026-42990",
          "CVE-2026-44806",
          "CVE-2026-49164",
          "CVE-2026-49165",
          "CVE-2026-49167",
          "CVE-2026-49168",
          "CVE-2026-49170",
          "CVE-2026-49171",
          "CVE-2026-49172",
          "CVE-2026-49174",
          "CVE-2026-49175",
          "CVE-2026-49176",
          "CVE-2026-49177",
          "CVE-2026-49178",
          "CVE-2026-49180",
          "CVE-2026-49183",
          "CVE-2026-49184",
          "CVE-2026-49783",
          "CVE-2026-49784",
          "CVE-2026-49787",
          "CVE-2026-49788",
          "CVE-2026-49789",
          "CVE-2026-49790",
          "CVE-2026-49791",
          "CVE-2026-49792",
          "CVE-2026-49793",
          "CVE-2026-49794",
          "CVE-2026-49795",
          "CVE-2026-49796",
          "CVE-2026-49797",
          "CVE-2026-49798",
          "CVE-2026-49799",
          "CVE-2026-49800",
          "CVE-2026-49801",
          "CVE-2026-49803",
          "CVE-2026-49804",
          "CVE-2026-49805",
          "CVE-2026-49807",
          "CVE-2026-50293",
          "CVE-2026-50294",
          "CVE-2026-50296",
          "CVE-2026-50297",
          "CVE-2026-50298",
          "CVE-2026-50299",
          "CVE-2026-50300",
          "CVE-2026-50302",
          "CVE-2026-50303",
          "CVE-2026-50306",
          "CVE-2026-50307",
          "CVE-2026-50308",
          "CVE-2026-50309",
          "CVE-2026-50310",
          "CVE-2026-50311",
          "CVE-2026-50312",
          "CVE-2026-50313",
          "CVE-2026-50316",
          "CVE-2026-50318",
          "CVE-2026-50321",
          "CVE-2026-50325",
          "CVE-2026-50326",
          "CVE-2026-50329",
          "CVE-2026-50330",
          "CVE-2026-50331",
          "CVE-2026-50332",
          "CVE-2026-50333",
          "CVE-2026-50334",
          "CVE-2026-50335",
          "CVE-2026-50337",
          "CVE-2026-50339",
          "CVE-2026-50341",
          "CVE-2026-50343",
          "CVE-2026-50344",
          "CVE-2026-50346",
          "CVE-2026-50347",
          "CVE-2026-50348",
          "CVE-2026-50350",
          "CVE-2026-50351",
          "CVE-2026-50352",
          "CVE-2026-50354",
          "CVE-2026-50356",
          "CVE-2026-50357",
          "CVE-2026-50358",
          "CVE-2026-50359",
          "CVE-2026-50360",
          "CVE-2026-50362",
          "CVE-2026-50363",
          "CVE-2026-50364",
          "CVE-2026-50365",
          "CVE-2026-50366",
          "CVE-2026-50367",
          "CVE-2026-50369",
          "CVE-2026-50371",
          "CVE-2026-50372",
          "CVE-2026-50373",
          "CVE-2026-50374",
          "CVE-2026-50375",
          "CVE-2026-50376",
          "CVE-2026-50377",
          "CVE-2026-50378",
          "CVE-2026-50380",
          "CVE-2026-50381",
          "CVE-2026-50382",
          "CVE-2026-50383",
          "CVE-2026-50384",
          "CVE-2026-50386",
          "CVE-2026-50387",
          "CVE-2026-50388",
          "CVE-2026-50389",
          "CVE-2026-50390",
          "CVE-2026-50391",
          "CVE-2026-50394",
          "CVE-2026-50397",
          "CVE-2026-50399",
          "CVE-2026-50400",
          "CVE-2026-50401",
          "CVE-2026-50402",
          "CVE-2026-50405",
          "CVE-2026-50406",
          "CVE-2026-50407",
          "CVE-2026-50409",
          "CVE-2026-50410",
          "CVE-2026-50411",
          "CVE-2026-50412",
          "CVE-2026-50415",
          "CVE-2026-50417",
          "CVE-2026-50419",
          "CVE-2026-50421",
          "CVE-2026-50422",
          "CVE-2026-50423",
          "CVE-2026-50425",
          "CVE-2026-50427",
          "CVE-2026-50429",
          "CVE-2026-50430",
          "CVE-2026-50431",
          "CVE-2026-50432",
          "CVE-2026-50433",
          "CVE-2026-50434",
          "CVE-2026-50435",
          "CVE-2026-50437",
          "CVE-2026-50439",
          "CVE-2026-50441",
          "CVE-2026-50442",
          "CVE-2026-50445",
          "CVE-2026-50447",
          "CVE-2026-50448",
          "CVE-2026-50449",
          "CVE-2026-50450",
          "CVE-2026-50451",
          "CVE-2026-50452",
          "CVE-2026-50453",
          "CVE-2026-50455",
          "CVE-2026-50456",
          "CVE-2026-50457",
          "CVE-2026-50459",
          "CVE-2026-50460",
          "CVE-2026-50461",
          "CVE-2026-50462",
          "CVE-2026-50463",
          "CVE-2026-50469",
          "CVE-2026-50470",
          "CVE-2026-50471",
          "CVE-2026-50473",
          "CVE-2026-50474",
          "CVE-2026-50475",
          "CVE-2026-50476",
          "CVE-2026-50477",
          "CVE-2026-50478",
          "CVE-2026-50479",
          "CVE-2026-50482",
          "CVE-2026-50484",
          "CVE-2026-50485",
          "CVE-2026-50486",
          "CVE-2026-50489",
          "CVE-2026-50490",
          "CVE-2026-50491",
          "CVE-2026-50492",
          "CVE-2026-50493",
          "CVE-2026-50494",
          "CVE-2026-50495",
          "CVE-2026-50496",
          "CVE-2026-50497",
          "CVE-2026-50498",
          "CVE-2026-50499",
          "CVE-2026-50500",
          "CVE-2026-50502",
          "CVE-2026-50504",
          "CVE-2026-50505",
          "CVE-2026-50509",
          "CVE-2026-50647",
          "CVE-2026-50655",
          "CVE-2026-50661",
          "CVE-2026-50666",
          "CVE-2026-50667",
          "CVE-2026-50668",
          "CVE-2026-50669",
          "CVE-2026-50670",
          "CVE-2026-50672",
          "CVE-2026-50673",
          "CVE-2026-50680",
          "CVE-2026-50681",
          "CVE-2026-50682",
          "CVE-2026-50686",
          "CVE-2026-50688",
          "CVE-2026-50689",
          "CVE-2026-50690",
          "CVE-2026-50692",
          "CVE-2026-50694",
          "CVE-2026-50695",
          "CVE-2026-50696",
          "CVE-2026-50697",
          "CVE-2026-54107",
          "CVE-2026-54109",
          "CVE-2026-54112",
          "CVE-2026-54114",
          "CVE-2026-54115",
          "CVE-2026-54119",
          "CVE-2026-54122",
          "CVE-2026-54124",
          "CVE-2026-54125",
          "CVE-2026-54126",
          "CVE-2026-54128",
          "CVE-2026-54129",
          "CVE-2026-54132",
          "CVE-2026-54982",
          "CVE-2026-54983",
          "CVE-2026-54986",
          "CVE-2026-54987",
          "CVE-2026-54989",
          "CVE-2026-54992",
          "CVE-2026-54993",
          "CVE-2026-54995",
          "CVE-2026-54997",
          "CVE-2026-54999",
          "CVE-2026-55003",
          "CVE-2026-55004",
          "CVE-2026-56168",
          "CVE-2026-56173",
          "CVE-2026-56175",
          "CVE-2026-56176",
          "CVE-2026-56182",
          "CVE-2026-56184",
          "CVE-2026-56186",
          "CVE-2026-56188",
          "CVE-2026-56189",
          "CVE-2026-56190",
          "CVE-2026-56194",
          "CVE-2026-56643",
          "CVE-2026-56644",
          "CVE-2026-56647",
          "CVE-2026-56648",
          "CVE-2026-56649",
          "CVE-2026-56650",
          "CVE-2026-57083",
          "CVE-2026-57084",
          "CVE-2026-57085",
          "CVE-2026-57087",
          "CVE-2026-57089",
          "CVE-2026-57090",
          "CVE-2026-57091",
          "CVE-2026-57092",
          "CVE-2026-57093",
          "CVE-2026-57094",
          "CVE-2026-57095",
          "CVE-2026-57096",
          "CVE-2026-57097",
          "CVE-2026-57976",
          "CVE-2026-57979",
          "CVE-2026-57982",
          "CVE-2026-58526",
          "CVE-2026-58528",
          "CVE-2026-58530",
          "CVE-2026-58531",
          "CVE-2026-58532",
          "CVE-2026-58533",
          "CVE-2026-58534",
          "CVE-2026-58535",
          "CVE-2026-58536",
          "CVE-2026-58538",
          "CVE-2026-58539",
          "CVE-2026-58540",
          "CVE-2026-58541",
          "CVE-2026-58545",
          "CVE-2026-58546",
          "CVE-2026-58547",
          "CVE-2026-58594",
          "CVE-2026-58601",
          "CVE-2026-58608",
          "CVE-2026-58609",
          "CVE-2026-58610",
          "CVE-2026-58613",
          "CVE-2026-58614",
          "CVE-2026-58619",
          "CVE-2026-58626",
          "CVE-2026-58628",
          "CVE-2026-58629",
          "CVE-2026-58632",
          "CVE-2026-58635",
          "CVE-2026-58637",
          "CVE-2026-58638",
          "CVE-2026-58640"
        ],
        "details": [
          {
            "id": "CVE-2026-33842",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39646,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-34328",
            "title": "Windows Audio Service Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39644,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-34346",
            "title": "Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability",
            "summary": "Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0027,
            "epssPercentile": 0.18916,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-34348",
            "title": "Windows Event Logging Service Information Disclosure Vulnerability",
            "summary": "Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00907,
            "epssPercentile": 0.57588,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-34349",
            "title": "Windows Media Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39645,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-40378",
            "title": "Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability",
            "summary": "Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65473,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-40400",
            "title": "Windows PowerShell Remote Code Execution Vulnerability",
            "summary": "Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00868,
            "epssPercentile": 0.56393,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-40422",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33743,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-41087",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39643,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-42900",
            "title": "Microsoft Windows App Store Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00542,
            "epssPercentile": 0.43631,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-42975",
            "title": "Windows Bluetooth Port Driver Remote Code Execution",
            "summary": "Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00536,
            "epssPercentile": 0.43257,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-42982",
            "title": "Windows Secure Kernel Mode Elevation of Privilege Vulnerability",
            "summary": "Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26114,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-42990",
            "title": "SQL Server ODBC driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59786,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-44806",
            "title": "Windows Secure Channel Denial of Service Vulnerability",
            "summary": "Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65471,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49164",
            "title": "Windows Active Directory Domain Services Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53952,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49165",
            "title": "Microsoft Windows App Store Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00338,
            "epssPercentile": 0.26611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49167",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 4.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0035,
            "epssPercentile": 0.28037,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49168",
            "title": "Storage Spaces Direct Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36763,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49170",
            "title": "Windows StateRepository API Server file Elevation of Privilege Vulnerability",
            "summary": "Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.2211,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49171",
            "title": "Windows Speech Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.003,
            "epssPercentile": 0.22345,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49172",
            "title": "Windows FTP Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59785,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49174",
            "title": "DNS Client Tampering Vulnerability",
            "summary": "Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0027,
            "epssPercentile": 0.18886,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49175",
            "title": "Windows DNS Client Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26114,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49176",
            "title": "Windows WalletService Elevation of Privilege Vulnerability",
            "summary": "Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00471,
            "epssPercentile": 0.39116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49177",
            "title": "Windows TCP/IP Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00443,
            "epssPercentile": 0.37172,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49178",
            "title": "Windows Active Directory Domain Services Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.57789,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49180",
            "title": "Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00444,
            "epssPercentile": 0.37219,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49183",
            "title": "Windows Clipboard Server Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10168,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49184",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00337,
            "epssPercentile": 0.26479,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49783",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26114,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49784",
            "title": "Microsoft Windows App Store Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10169,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49787",
            "title": "HTTP.sys Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65471,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49788",
            "title": "HTTP/2 Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49789",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29002,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49790",
            "title": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
            "summary": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29001,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49791",
            "title": "Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0038,
            "epssPercentile": 0.31138,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49792",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26115,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49793",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26113,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49794",
            "title": "Windows USB Audio Class Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00468,
            "epssPercentile": 0.3893,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49795",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26115,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49796",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49797",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38802,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49798",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.",
            "score": 9.3,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00364,
            "epssPercentile": 0.29518,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49799",
            "title": "Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability",
            "summary": "Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01138,
            "epssPercentile": 0.64468,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49800",
            "title": "Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26115,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49801",
            "title": "Windows SMB Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33744,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49803",
            "title": "Windows AppX Deployment Extensions Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.1017,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49804",
            "title": "Windows USB Video Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows USB Video Driver allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00483,
            "epssPercentile": 0.39895,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49805",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00236,
            "epssPercentile": 0.14488,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49807",
            "title": "Windows DirectX Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows DirectX allows an unauthorized attacker to disclose information locally.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00506,
            "epssPercentile": 0.41392,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50293",
            "title": "Windows Internal Task Bar Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Internal Task Bar allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50294",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized attacker to disclose information locally.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00506,
            "epssPercentile": 0.41392,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50296",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Graphics Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18079,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50297",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00236,
            "epssPercentile": 0.14488,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50298",
            "title": "Windows Spaceport.sys Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36765,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50299",
            "title": "Windows Storage Spaces Direct Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36764,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50300",
            "title": "Windows DWM Core Library Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50302",
            "title": "Windows Cryptographic Services Security Feature Bypass Vulnerability",
            "summary": "Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 4.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00334,
            "epssPercentile": 0.2625,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50303",
            "title": "Windows Key Guard Security Feature Bypass Vulnerability",
            "summary": "Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0027,
            "epssPercentile": 0.18916,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50306",
            "title": "Windows TCP/IP Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26104,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50307",
            "title": "Windows TCP/IP Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20052,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50308",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38802,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50309",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26104,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50310",
            "title": "Windows Human Interface Device Information Disclosure Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information locally.",
            "score": 4.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23556,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50311",
            "title": "Windows Server Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50312",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 4.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0035,
            "epssPercentile": 0.28037,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50313",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38794,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50316",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39648,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50318",
            "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26103,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50321",
            "title": "Windows USB Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11649,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50325",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00236,
            "epssPercentile": 0.14488,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50326",
            "title": "Windows Unified Consent System Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Unified Consent System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50329",
            "title": "Microsoft DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50330",
            "title": "Windows Remote Desktop Client Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01252,
            "epssPercentile": 0.6748,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50331",
            "title": "Windows Application Model Core API Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Application Model allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50332",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50333",
            "title": "Windows Spaceport.sys Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50334",
            "title": "Windows Push Notification Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Notification allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39645,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50335",
            "title": "Windows Operating Systems Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50337",
            "title": "Windows Notification Elevation of Privilege Vulnerability",
            "summary": "Incorrect type conversion or cast in Windows Notification allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26104,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50339",
            "title": "Windows Push Notification Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39645,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50341",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33741,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50343",
            "title": "Microsoft Install Service Elevation of Privilege Vulnerability",
            "summary": "Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50344",
            "title": "Windows OLE Elevation of Privilege Vulnerability",
            "summary": "Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50346",
            "title": "Netlogon RPC Elevation of Privilege Vulnerability",
            "summary": "Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50347",
            "title": "Windows Data.dll Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38792,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50348",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0036,
            "epssPercentile": 0.29103,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50350",
            "title": "Windows Trusted Runtime Interface Driver Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39646,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50351",
            "title": "Windows Audio Compression Manager (ACM) Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50352",
            "title": "Windows Cryptographic Services Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50354",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26129,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50356",
            "title": "Microsoft Windows App Store Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10168,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50357",
            "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50358",
            "title": "Windows Media Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Media allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20051,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50359",
            "title": "Microsoft XML Core Services Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20051,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50360",
            "title": "Windows SMB Server Elevation of Privilege Vulnerability",
            "summary": "Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00778,
            "epssPercentile": 0.53532,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50362",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38801,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50363",
            "title": "Windows Push Notifications Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26102,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50364",
            "title": "Windows Backup Service Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows Server Backup allows an authorized attacker to elevate privileges locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00469,
            "epssPercentile": 0.38948,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50365",
            "title": "Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability",
            "summary": "Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00542,
            "epssPercentile": 0.43604,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50366",
            "title": "Windows Active Directory Domain Services Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01138,
            "epssPercentile": 0.64468,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50367",
            "title": "Windows Sensor Data Service Elevation of Privilege Vulnerability",
            "summary": "Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26103,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50369",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00701,
            "epssPercentile": 0.50891,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50371",
            "title": "Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows LUAFV allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10167,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50372",
            "title": "Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability",
            "summary": "Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18081,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50373",
            "title": "Windows Search Service Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50374",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00347,
            "epssPercentile": 0.27656,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50375",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DirectX allows an authorized attacker to elevate privileges locally.",
            "score": 6.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00295,
            "epssPercentile": 0.21728,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50376",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50377",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00409,
            "epssPercentile": 0.34158,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50378",
            "title": "Windows Key Guard Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Key Guard allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11649,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50380",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.",
            "score": 9.6,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.54859,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50381",
            "title": "Composite Image File System driver (cimfs.sys) Information Disclosure Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Composite Image File System Driver allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33744,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50382",
            "title": "DirectX Graphics Kernel Remote Code Execution Vulnerability",
            "summary": "Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50383",
            "title": "Windows Print Spooler Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33741,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50384",
            "title": "Windows Clip Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clip Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10168,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50386",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38791,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50387",
            "title": "Windows GDI Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26111,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50388",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38797,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50389",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39644,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50390",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20053,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50391",
            "title": "Windows Group Policy Elevation of Privilege Vulnerability",
            "summary": "Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.2211,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50394",
            "title": "Windows Media Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39643,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50397",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18081,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50399",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26111,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50400",
            "title": "Windows App Package Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.2611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50401",
            "title": "Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33744,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50402",
            "title": "NTFS Elevation of Privilege Vulnerability",
            "summary": "Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.2611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50405",
            "title": "Windows Filtering Platform Elevation of Privilege Vulnerability",
            "summary": "Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50406",
            "title": "Windows Backup Engine Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Backup Engine allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20052,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50407",
            "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50409",
            "title": "Windows Overlay Filter Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Overlay Filter allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50410",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18079,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50411",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50412",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50415",
            "title": "Windows Media Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Media allows an unauthorized attacker to disclose information over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0086,
            "epssPercentile": 0.56162,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50417",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26111,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50419",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.",
            "score": 3.3,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00458,
            "epssPercentile": 0.38211,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50421",
            "title": "Windows Connected User Experiences and Telemetry Elevation of Privilege Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.2611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50422",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50423",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50425",
            "title": "Windows Internal System User Profile Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Internal System User Profile allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50427",
            "title": "Content Delivery Manager Elevation of Privilege Vulnerability",
            "summary": "Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17026,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50429",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network.",
            "score": 8.2,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01069,
            "epssPercentile": 0.62606,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50430",
            "title": "Windows Push Notification Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39648,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50431",
            "title": "Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability",
            "summary": "Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39648,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50432",
            "title": "Window Virtual Filtering Platform (VFP) Denial of Service Vulnerability",
            "summary": "Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized attacker to deny service over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00953,
            "epssPercentile": 0.59049,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50433",
            "title": "Windows Media Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Media allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50434",
            "title": "Windows Push Notification Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50435",
            "title": "Windows Overlay Filter Elevation of Privilege Vulnerability",
            "summary": "Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50437",
            "title": "Windows DWM Core Library Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50439",
            "title": "Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53953,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50441",
            "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
            "summary": "Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.2611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50442",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39646,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50445",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58032,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50447",
            "title": "Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59787,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50448",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38799,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50449",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18082,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50450",
            "title": "Windows Network Connections Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10166,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50451",
            "title": "Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00307,
            "epssPercentile": 0.23134,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50452",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0036,
            "epssPercentile": 0.29103,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50453",
            "title": "Windows USB Audio Class Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0051,
            "epssPercentile": 0.41673,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50455",
            "title": "Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33743,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50456",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39646,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50457",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17027,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50459",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22679,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50460",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00542,
            "epssPercentile": 0.4363,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50461",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38801,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50462",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00457,
            "epssPercentile": 0.38194,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50463",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01027,
            "epssPercentile": 0.61357,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50469",
            "title": "Windows Projected File System Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows Projected File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0037,
            "epssPercentile": 0.30149,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50470",
            "title": "Windows Network Policy Server SNMP Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01027,
            "epssPercentile": 0.61358,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50471",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38793,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50473",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39644,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50474",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.54859,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50475",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.00375,
            "epssPercentile": 0.30678,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Medium technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50476",
            "title": "Windows Network Connections Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Windows allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20051,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50477",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.261,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50478",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26097,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50479",
            "title": "Windows USB Hub Driver Elevation of Privilege Vulnerability",
            "summary": "Untrusted pointer dereference in Windows USB Hub Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26097,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50482",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29001,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50484",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26112,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50485",
            "title": "Windows Hyper-V Denial of Service Vulnerability",
            "summary": "Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.",
            "score": 4.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00656,
            "epssPercentile": 0.49112,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50486",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26097,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50489",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50490",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20054,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50491",
            "title": "Code Integrity DLL (ci.dll) Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20054,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50492",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36764,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50493",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26098,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50494",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26098,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50495",
            "title": "DNS Client Tampering Vulnerability",
            "summary": "Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00302,
            "epssPercentile": 0.22534,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50496",
            "title": "Windows Network Policy Server SNMP Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50497",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58032,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50498",
            "title": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
            "summary": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00363,
            "epssPercentile": 0.29377,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50499",
            "title": "Windows Print Spooler Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50500",
            "title": "Windows Netlogon Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00742,
            "epssPercentile": 0.52348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50502",
            "title": "Windows Event Logging Service Remote Code Execution Vulnerability",
            "summary": "Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00654,
            "epssPercentile": 0.49042,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50504",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.5803,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50505",
            "title": "Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00742,
            "epssPercentile": 0.52348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50509",
            "title": "Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability",
            "summary": "Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0353,
            "epssPercentile": 0.88474,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50647",
            "title": "Active Directory Federation Server Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50655",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38797,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50661",
            "title": "Windows BitLocker Security Feature Bypass Vulnerability",
            "summary": "Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00481,
            "epssPercentile": 0.39822,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50666",
            "title": "Windows Remote Access Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.5779,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50667",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11651,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50668",
            "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36764,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50669",
            "title": "Windows Telephony Server Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.1017,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50670",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26096,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50672",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10166,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50673",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.1165,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50680",
            "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally.",
            "score": 8.2,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00338,
            "epssPercentile": 0.26665,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50681",
            "title": "Windows Secure Channel Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39645,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50682",
            "title": "Active Directory Denial of Service Vulnerability",
            "summary": "Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58293,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50686",
            "title": "Windows OLE Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00707,
            "epssPercentile": 0.5113,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50688",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20053,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50689",
            "title": "Windows Clipboard Server Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17026,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50690",
            "title": "Windows SMB Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50692",
            "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.261,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50694",
            "title": "Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53953,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50695",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65468,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50696",
            "title": "Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50697",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00395,
            "epssPercentile": 0.32743,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54107",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11651,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54109",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54112",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10171,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54114",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54115",
            "title": "Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26115,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54119",
            "title": "Windows Active Directory Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54122",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00364,
            "epssPercentile": 0.29518,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54124",
            "title": "Windows Terminal Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.388,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54125",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17027,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54126",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58034,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54128",
            "title": "Windows DHCP Client Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00364,
            "epssPercentile": 0.29519,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54129",
            "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20054,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54132",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36764,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54982",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00535,
            "epssPercentile": 0.43236,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54983",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65471,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54986",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26113,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54987",
            "title": "Windows Overlay Filter Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54989",
            "title": "Quality Windows Audio/Video Experience (QWAVE) Elevation of Privilege Vulnerability",
            "summary": "Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20052,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54992",
            "title": "Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00337,
            "epssPercentile": 0.26479,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54993",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38795,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54995",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53953,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54997",
            "title": "Windows SMB Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54999",
            "title": "Windows TCP/IP Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0041,
            "epssPercentile": 0.34281,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55003",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55004",
            "title": "Windows Print Configuration Elevation of Privilege Vulnerability",
            "summary": "Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56168",
            "title": "Windows SMB Server Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01138,
            "epssPercentile": 0.64469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56173",
            "title": "Windows WebView Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18078,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56175",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26112,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56176",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26112,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56182",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26112,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56184",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39643,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56186",
            "title": "Windows Secure Channel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01106,
            "epssPercentile": 0.63644,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56188",
            "title": "Windows Server Network driver Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00607,
            "epssPercentile": 0.46852,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56189",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00393,
            "epssPercentile": 0.32499,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56190",
            "title": "Remote Desktop Protocol Remote Code Execution Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59787,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56194",
            "title": "Windows NFS Server Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.5779,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56643",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56644",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56647",
            "title": "Windows Remote Access Service Infrastructure Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.57789,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56648",
            "title": "Windows NFS Server Elevation of Privilege Vulnerability",
            "summary": "Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00509,
            "epssPercentile": 0.41581,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56649",
            "title": "Windows Network File System Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File System allows an unauthorized attacker to execute code over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00699,
            "epssPercentile": 0.50808,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56650",
            "title": "Windows Network File System Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57083",
            "title": "Windows Media Photo Codec Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.4355,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57084",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.43549,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57085",
            "title": "Windows Print Spooler Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0037,
            "epssPercentile": 0.30143,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57087",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53969,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57089",
            "title": "Windows SMB Server Network Transport Driver (srvnet.sys) Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00665,
            "epssPercentile": 0.49498,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57090",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.54858,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57091",
            "title": "Windows File History Service Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows File History Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57092",
            "title": "Microsoft Windows VMSwitch Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.",
            "score": 9.9,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.57791,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57093",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20053,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57094",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.54859,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57095",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00489,
            "epssPercentile": 0.40353,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57096",
            "title": "Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57097",
            "title": "Microsoft XML Security Feature Bypass Vulnerability",
            "summary": "Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack.",
            "score": 6.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00503,
            "epssPercentile": 0.41172,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57976",
            "title": "Windows Active Directory Domain Services Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01138,
            "epssPercentile": 0.64468,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57979",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58034,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57982",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00995,
            "epssPercentile": 0.60375,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58526",
            "title": "Windows Storage Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Storage allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11648,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58528",
            "title": "Windows USB Audio Class Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00524,
            "epssPercentile": 0.42584,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58530",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00363,
            "epssPercentile": 0.29377,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58531",
            "title": "Windows SMB Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00509,
            "epssPercentile": 0.41581,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58532",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.261,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58533",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58033,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58534",
            "title": "Windows Input Method Editor (IME) Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26095,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58535",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58536",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26095,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58538",
            "title": "Windows Bluetooth Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26101,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58539",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58033,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58540",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58541",
            "title": "Microsoft DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26102,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58545",
            "title": "Windows Kernel Security Feature Bypass Vulnerability",
            "summary": "Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0035,
            "epssPercentile": 0.27951,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58546",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58033,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58547",
            "title": "Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00407,
            "epssPercentile": 0.33974,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58594",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.5486,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58601",
            "title": "Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability",
            "summary": "Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26102,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58608",
            "title": "Windows Print Spooler Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00569,
            "epssPercentile": 0.45031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58609",
            "title": "Windows Graphics Component Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38794,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58610",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38797,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58613",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.00377,
            "epssPercentile": 0.30833,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58614",
            "title": "Windows Kernel Security Feature Bypass Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33743,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58619",
            "title": "Windows Sensor Data Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.1808,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58626",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.57789,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58628",
            "title": "Windows Wireless Network Manager Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10171,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58629",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.1808,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58632",
            "title": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26101,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58635",
            "title": "Windows Narrator Braille Elevation of Privilege Vulnerability",
            "summary": "Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00322,
            "epssPercentile": 0.24873,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58637",
            "title": "Windows Client-Side Caching Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18082,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58638",
            "title": "Windows Boot Loader Security Feature Bypass Vulnerability",
            "summary": "Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.",
            "score": 6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00235,
            "epssPercentile": 0.14327,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58640",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29001,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.9,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-57092",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-windows-kb5099540",
      "slug": "microsoft-2026-07-windows-kb5099540",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5099540",
      "title": "Deploy Microsoft Windows security update KB5099540",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5099540",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Windows Server 2022, Windows Server 2022 (Server Core installation)",
      "platform": "Windows",
      "release_version": "10.0.20348.5386",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 325 linked CVEs for Windows Server 2022, Windows Server 2022 (Server Core installation). Microsoft reports exploitation for CVE-2026-56155.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 325,
        "ids": [
          "CVE-2026-33842",
          "CVE-2026-34328",
          "CVE-2026-34346",
          "CVE-2026-34348",
          "CVE-2026-34349",
          "CVE-2026-40378",
          "CVE-2026-40400",
          "CVE-2026-40422",
          "CVE-2026-41087",
          "CVE-2026-42900",
          "CVE-2026-42975",
          "CVE-2026-42982",
          "CVE-2026-42990",
          "CVE-2026-44806",
          "CVE-2026-48564",
          "CVE-2026-49164",
          "CVE-2026-49165",
          "CVE-2026-49167",
          "CVE-2026-49168",
          "CVE-2026-49170",
          "CVE-2026-49171",
          "CVE-2026-49172",
          "CVE-2026-49174",
          "CVE-2026-49175",
          "CVE-2026-49176",
          "CVE-2026-49177",
          "CVE-2026-49178",
          "CVE-2026-49180",
          "CVE-2026-49181",
          "CVE-2026-49183",
          "CVE-2026-49184",
          "CVE-2026-49783",
          "CVE-2026-49784",
          "CVE-2026-49787",
          "CVE-2026-49788",
          "CVE-2026-49789",
          "CVE-2026-49790",
          "CVE-2026-49791",
          "CVE-2026-49792",
          "CVE-2026-49793",
          "CVE-2026-49794",
          "CVE-2026-49795",
          "CVE-2026-49796",
          "CVE-2026-49797",
          "CVE-2026-49798",
          "CVE-2026-49799",
          "CVE-2026-49800",
          "CVE-2026-49801",
          "CVE-2026-49803",
          "CVE-2026-49804",
          "CVE-2026-49805",
          "CVE-2026-49807",
          "CVE-2026-50294",
          "CVE-2026-50296",
          "CVE-2026-50297",
          "CVE-2026-50298",
          "CVE-2026-50299",
          "CVE-2026-50300",
          "CVE-2026-50302",
          "CVE-2026-50303",
          "CVE-2026-50304",
          "CVE-2026-50306",
          "CVE-2026-50307",
          "CVE-2026-50308",
          "CVE-2026-50309",
          "CVE-2026-50310",
          "CVE-2026-50311",
          "CVE-2026-50312",
          "CVE-2026-50313",
          "CVE-2026-50316",
          "CVE-2026-50318",
          "CVE-2026-50321",
          "CVE-2026-50324",
          "CVE-2026-50325",
          "CVE-2026-50328",
          "CVE-2026-50329",
          "CVE-2026-50330",
          "CVE-2026-50331",
          "CVE-2026-50332",
          "CVE-2026-50333",
          "CVE-2026-50334",
          "CVE-2026-50335",
          "CVE-2026-50337",
          "CVE-2026-50339",
          "CVE-2026-50341",
          "CVE-2026-50343",
          "CVE-2026-50344",
          "CVE-2026-50346",
          "CVE-2026-50347",
          "CVE-2026-50348",
          "CVE-2026-50351",
          "CVE-2026-50352",
          "CVE-2026-50354",
          "CVE-2026-50355",
          "CVE-2026-50356",
          "CVE-2026-50357",
          "CVE-2026-50358",
          "CVE-2026-50359",
          "CVE-2026-50360",
          "CVE-2026-50362",
          "CVE-2026-50363",
          "CVE-2026-50365",
          "CVE-2026-50366",
          "CVE-2026-50367",
          "CVE-2026-50368",
          "CVE-2026-50369",
          "CVE-2026-50370",
          "CVE-2026-50371",
          "CVE-2026-50372",
          "CVE-2026-50373",
          "CVE-2026-50374",
          "CVE-2026-50375",
          "CVE-2026-50376",
          "CVE-2026-50377",
          "CVE-2026-50378",
          "CVE-2026-50380",
          "CVE-2026-50381",
          "CVE-2026-50382",
          "CVE-2026-50383",
          "CVE-2026-50384",
          "CVE-2026-50386",
          "CVE-2026-50387",
          "CVE-2026-50388",
          "CVE-2026-50389",
          "CVE-2026-50390",
          "CVE-2026-50391",
          "CVE-2026-50394",
          "CVE-2026-50397",
          "CVE-2026-50399",
          "CVE-2026-50400",
          "CVE-2026-50401",
          "CVE-2026-50402",
          "CVE-2026-50405",
          "CVE-2026-50407",
          "CVE-2026-50409",
          "CVE-2026-50410",
          "CVE-2026-50411",
          "CVE-2026-50412",
          "CVE-2026-50415",
          "CVE-2026-50417",
          "CVE-2026-50418",
          "CVE-2026-50419",
          "CVE-2026-50421",
          "CVE-2026-50422",
          "CVE-2026-50423",
          "CVE-2026-50426",
          "CVE-2026-50429",
          "CVE-2026-50430",
          "CVE-2026-50431",
          "CVE-2026-50432",
          "CVE-2026-50433",
          "CVE-2026-50434",
          "CVE-2026-50435",
          "CVE-2026-50437",
          "CVE-2026-50439",
          "CVE-2026-50441",
          "CVE-2026-50442",
          "CVE-2026-50444",
          "CVE-2026-50445",
          "CVE-2026-50447",
          "CVE-2026-50448",
          "CVE-2026-50449",
          "CVE-2026-50450",
          "CVE-2026-50451",
          "CVE-2026-50452",
          "CVE-2026-50453",
          "CVE-2026-50455",
          "CVE-2026-50456",
          "CVE-2026-50459",
          "CVE-2026-50460",
          "CVE-2026-50461",
          "CVE-2026-50462",
          "CVE-2026-50463",
          "CVE-2026-50469",
          "CVE-2026-50470",
          "CVE-2026-50471",
          "CVE-2026-50473",
          "CVE-2026-50474",
          "CVE-2026-50475",
          "CVE-2026-50476",
          "CVE-2026-50477",
          "CVE-2026-50478",
          "CVE-2026-50479",
          "CVE-2026-50482",
          "CVE-2026-50484",
          "CVE-2026-50485",
          "CVE-2026-50489",
          "CVE-2026-50490",
          "CVE-2026-50491",
          "CVE-2026-50492",
          "CVE-2026-50493",
          "CVE-2026-50494",
          "CVE-2026-50495",
          "CVE-2026-50496",
          "CVE-2026-50497",
          "CVE-2026-50498",
          "CVE-2026-50499",
          "CVE-2026-50500",
          "CVE-2026-50502",
          "CVE-2026-50504",
          "CVE-2026-50505",
          "CVE-2026-50518",
          "CVE-2026-50647",
          "CVE-2026-50655",
          "CVE-2026-50661",
          "CVE-2026-50666",
          "CVE-2026-50667",
          "CVE-2026-50668",
          "CVE-2026-50669",
          "CVE-2026-50670",
          "CVE-2026-50672",
          "CVE-2026-50673",
          "CVE-2026-50680",
          "CVE-2026-50681",
          "CVE-2026-50682",
          "CVE-2026-50683",
          "CVE-2026-50684",
          "CVE-2026-50685",
          "CVE-2026-50686",
          "CVE-2026-50688",
          "CVE-2026-50689",
          "CVE-2026-50690",
          "CVE-2026-50692",
          "CVE-2026-50694",
          "CVE-2026-50695",
          "CVE-2026-50696",
          "CVE-2026-50697",
          "CVE-2026-54107",
          "CVE-2026-54109",
          "CVE-2026-54112",
          "CVE-2026-54114",
          "CVE-2026-54115",
          "CVE-2026-54119",
          "CVE-2026-54121",
          "CVE-2026-54122",
          "CVE-2026-54124",
          "CVE-2026-54125",
          "CVE-2026-54126",
          "CVE-2026-54127",
          "CVE-2026-54128",
          "CVE-2026-54129",
          "CVE-2026-54982",
          "CVE-2026-54983",
          "CVE-2026-54986",
          "CVE-2026-54987",
          "CVE-2026-54989",
          "CVE-2026-54992",
          "CVE-2026-54993",
          "CVE-2026-54995",
          "CVE-2026-54997",
          "CVE-2026-54999",
          "CVE-2026-55001",
          "CVE-2026-55003",
          "CVE-2026-55004",
          "CVE-2026-55144",
          "CVE-2026-56155",
          "CVE-2026-56159",
          "CVE-2026-56168",
          "CVE-2026-56173",
          "CVE-2026-56175",
          "CVE-2026-56176",
          "CVE-2026-56182",
          "CVE-2026-56184",
          "CVE-2026-56186",
          "CVE-2026-56188",
          "CVE-2026-56189",
          "CVE-2026-56190",
          "CVE-2026-56194",
          "CVE-2026-56643",
          "CVE-2026-56644",
          "CVE-2026-56647",
          "CVE-2026-56648",
          "CVE-2026-56649",
          "CVE-2026-56650",
          "CVE-2026-57083",
          "CVE-2026-57084",
          "CVE-2026-57085",
          "CVE-2026-57087",
          "CVE-2026-57088",
          "CVE-2026-57089",
          "CVE-2026-57090",
          "CVE-2026-57091",
          "CVE-2026-57092",
          "CVE-2026-57093",
          "CVE-2026-57094",
          "CVE-2026-57095",
          "CVE-2026-57096",
          "CVE-2026-57097",
          "CVE-2026-57976",
          "CVE-2026-57979",
          "CVE-2026-57982",
          "CVE-2026-58526",
          "CVE-2026-58527",
          "CVE-2026-58528",
          "CVE-2026-58530",
          "CVE-2026-58531",
          "CVE-2026-58532",
          "CVE-2026-58533",
          "CVE-2026-58534",
          "CVE-2026-58535",
          "CVE-2026-58536",
          "CVE-2026-58538",
          "CVE-2026-58539",
          "CVE-2026-58540",
          "CVE-2026-58541",
          "CVE-2026-58545",
          "CVE-2026-58546",
          "CVE-2026-58547",
          "CVE-2026-58594",
          "CVE-2026-58601",
          "CVE-2026-58608",
          "CVE-2026-58609",
          "CVE-2026-58610",
          "CVE-2026-58613",
          "CVE-2026-58614",
          "CVE-2026-58619",
          "CVE-2026-58626",
          "CVE-2026-58627",
          "CVE-2026-58628",
          "CVE-2026-58629",
          "CVE-2026-58632",
          "CVE-2026-58635",
          "CVE-2026-58637",
          "CVE-2026-58638",
          "CVE-2026-58640"
        ],
        "details": [
          {
            "id": "CVE-2026-33842",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39646,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-34328",
            "title": "Windows Audio Service Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39644,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-34346",
            "title": "Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability",
            "summary": "Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0027,
            "epssPercentile": 0.18916,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-34348",
            "title": "Windows Event Logging Service Information Disclosure Vulnerability",
            "summary": "Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00907,
            "epssPercentile": 0.57588,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-34349",
            "title": "Windows Media Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39645,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-40378",
            "title": "Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability",
            "summary": "Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65473,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-40400",
            "title": "Windows PowerShell Remote Code Execution Vulnerability",
            "summary": "Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00868,
            "epssPercentile": 0.56393,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-40422",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33743,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-41087",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39643,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-42900",
            "title": "Microsoft Windows App Store Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00542,
            "epssPercentile": 0.43631,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-42975",
            "title": "Windows Bluetooth Port Driver Remote Code Execution",
            "summary": "Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00536,
            "epssPercentile": 0.43257,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-42982",
            "title": "Windows Secure Kernel Mode Elevation of Privilege Vulnerability",
            "summary": "Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26114,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-42990",
            "title": "SQL Server ODBC driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59786,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-44806",
            "title": "Windows Secure Channel Denial of Service Vulnerability",
            "summary": "Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65471,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48564",
            "title": "DHCP Server Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.5779,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49164",
            "title": "Windows Active Directory Domain Services Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53952,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49165",
            "title": "Microsoft Windows App Store Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00338,
            "epssPercentile": 0.26611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49167",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 4.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0035,
            "epssPercentile": 0.28037,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49168",
            "title": "Storage Spaces Direct Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36763,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49170",
            "title": "Windows StateRepository API Server file Elevation of Privilege Vulnerability",
            "summary": "Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.2211,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49171",
            "title": "Windows Speech Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.003,
            "epssPercentile": 0.22345,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49172",
            "title": "Windows FTP Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59785,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49174",
            "title": "DNS Client Tampering Vulnerability",
            "summary": "Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0027,
            "epssPercentile": 0.18886,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49175",
            "title": "Windows DNS Client Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26114,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49176",
            "title": "Windows WalletService Elevation of Privilege Vulnerability",
            "summary": "Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00471,
            "epssPercentile": 0.39116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49177",
            "title": "Windows TCP/IP Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00443,
            "epssPercentile": 0.37172,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49178",
            "title": "Windows Active Directory Domain Services Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.57789,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49180",
            "title": "Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00444,
            "epssPercentile": 0.37219,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49181",
            "title": "Windows DHCP Client Elevation of Privilege Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01172,
            "epssPercentile": 0.65406,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49183",
            "title": "Windows Clipboard Server Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10168,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49184",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00337,
            "epssPercentile": 0.26479,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49783",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26114,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49784",
            "title": "Microsoft Windows App Store Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10169,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49787",
            "title": "HTTP.sys Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65471,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49788",
            "title": "HTTP/2 Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49789",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29002,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49790",
            "title": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
            "summary": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29001,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49791",
            "title": "Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0038,
            "epssPercentile": 0.31138,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49792",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26115,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49793",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26113,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49794",
            "title": "Windows USB Audio Class Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00468,
            "epssPercentile": 0.3893,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49795",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26115,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49796",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49797",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38802,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49798",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.",
            "score": 9.3,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00364,
            "epssPercentile": 0.29518,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49799",
            "title": "Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability",
            "summary": "Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01138,
            "epssPercentile": 0.64468,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49800",
            "title": "Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26115,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49801",
            "title": "Windows SMB Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33744,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49803",
            "title": "Windows AppX Deployment Extensions Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.1017,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49804",
            "title": "Windows USB Video Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows USB Video Driver allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00483,
            "epssPercentile": 0.39895,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49805",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00236,
            "epssPercentile": 0.14488,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49807",
            "title": "Windows DirectX Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows DirectX allows an unauthorized attacker to disclose information locally.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00506,
            "epssPercentile": 0.41392,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50294",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized attacker to disclose information locally.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00506,
            "epssPercentile": 0.41392,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50296",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Graphics Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18079,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50297",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00236,
            "epssPercentile": 0.14488,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50298",
            "title": "Windows Spaceport.sys Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36765,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50299",
            "title": "Windows Storage Spaces Direct Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36764,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50300",
            "title": "Windows DWM Core Library Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50302",
            "title": "Windows Cryptographic Services Security Feature Bypass Vulnerability",
            "summary": "Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 4.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00334,
            "epssPercentile": 0.2625,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50303",
            "title": "Windows Key Guard Security Feature Bypass Vulnerability",
            "summary": "Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0027,
            "epssPercentile": 0.18916,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50304",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50306",
            "title": "Windows TCP/IP Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26104,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50307",
            "title": "Windows TCP/IP Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20052,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50308",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38802,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50309",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26104,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50310",
            "title": "Windows Human Interface Device Information Disclosure Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information locally.",
            "score": 4.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23556,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50311",
            "title": "Windows Server Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50312",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 4.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0035,
            "epssPercentile": 0.28037,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50313",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38794,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50316",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39648,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50318",
            "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26103,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50321",
            "title": "Windows USB Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11649,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50324",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00855,
            "epssPercentile": 0.5598,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50325",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00236,
            "epssPercentile": 0.14488,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50328",
            "title": "Windows Server Update Service (WSUS) Tampering Vulnerability",
            "summary": "Uncaught exception in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01232,
            "epssPercentile": 0.67,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50329",
            "title": "Microsoft DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50330",
            "title": "Windows Remote Desktop Client Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01252,
            "epssPercentile": 0.6748,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50331",
            "title": "Windows Application Model Core API Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Application Model allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50332",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50333",
            "title": "Windows Spaceport.sys Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50334",
            "title": "Windows Push Notification Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Notification allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39645,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50335",
            "title": "Windows Operating Systems Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50337",
            "title": "Windows Notification Elevation of Privilege Vulnerability",
            "summary": "Incorrect type conversion or cast in Windows Notification allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26104,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50339",
            "title": "Windows Push Notification Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39645,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50341",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33741,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50343",
            "title": "Microsoft Install Service Elevation of Privilege Vulnerability",
            "summary": "Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50344",
            "title": "Windows OLE Elevation of Privilege Vulnerability",
            "summary": "Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50346",
            "title": "Netlogon RPC Elevation of Privilege Vulnerability",
            "summary": "Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50347",
            "title": "Windows Data.dll Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38792,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50348",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0036,
            "epssPercentile": 0.29103,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50351",
            "title": "Windows Audio Compression Manager (ACM) Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50352",
            "title": "Windows Cryptographic Services Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50354",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26129,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50355",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50356",
            "title": "Microsoft Windows App Store Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10168,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50357",
            "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50358",
            "title": "Windows Media Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Media allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20051,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50359",
            "title": "Microsoft XML Core Services Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20051,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50360",
            "title": "Windows SMB Server Elevation of Privilege Vulnerability",
            "summary": "Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00778,
            "epssPercentile": 0.53532,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50362",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38801,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50363",
            "title": "Windows Push Notifications Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26102,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50365",
            "title": "Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability",
            "summary": "Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00542,
            "epssPercentile": 0.43604,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50366",
            "title": "Windows Active Directory Domain Services Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01138,
            "epssPercentile": 0.64468,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50367",
            "title": "Windows Sensor Data Service Elevation of Privilege Vulnerability",
            "summary": "Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26103,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50368",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50369",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00701,
            "epssPercentile": 0.50891,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50370",
            "title": "DHCP Server Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00502,
            "epssPercentile": 0.41141,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50371",
            "title": "Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows LUAFV allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10167,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50372",
            "title": "Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability",
            "summary": "Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18081,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50373",
            "title": "Windows Search Service Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50374",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00347,
            "epssPercentile": 0.27656,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50375",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DirectX allows an authorized attacker to elevate privileges locally.",
            "score": 6.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00295,
            "epssPercentile": 0.21728,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50376",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50377",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00409,
            "epssPercentile": 0.34158,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50378",
            "title": "Windows Key Guard Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Key Guard allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11649,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50380",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.",
            "score": 9.6,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.54859,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50381",
            "title": "Composite Image File System driver (cimfs.sys) Information Disclosure Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Composite Image File System Driver allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33744,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50382",
            "title": "DirectX Graphics Kernel Remote Code Execution Vulnerability",
            "summary": "Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50383",
            "title": "Windows Print Spooler Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33741,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50384",
            "title": "Windows Clip Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clip Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10168,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50386",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38791,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50387",
            "title": "Windows GDI Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26111,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50388",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38797,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50389",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39644,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50390",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20053,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50391",
            "title": "Windows Group Policy Elevation of Privilege Vulnerability",
            "summary": "Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.2211,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50394",
            "title": "Windows Media Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39643,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50397",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18081,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50399",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26111,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50400",
            "title": "Windows App Package Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.2611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50401",
            "title": "Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33744,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50402",
            "title": "NTFS Elevation of Privilege Vulnerability",
            "summary": "Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.2611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50405",
            "title": "Windows Filtering Platform Elevation of Privilege Vulnerability",
            "summary": "Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50407",
            "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50409",
            "title": "Windows Overlay Filter Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Overlay Filter allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50410",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18079,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50411",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50412",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50415",
            "title": "Windows Media Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Media allows an unauthorized attacker to disclose information over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0086,
            "epssPercentile": 0.56162,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50417",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26111,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50418",
            "title": "Windows System Secure Feature Bypass Vulnerability",
            "summary": "Improper access control in Windows System allows an unauthorized attacker to bypass a security feature locally.",
            "score": 5.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00266,
            "epssPercentile": 0.18272,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50419",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.",
            "score": 3.3,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00458,
            "epssPercentile": 0.38211,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50421",
            "title": "Windows Connected User Experiences and Telemetry Elevation of Privilege Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.2611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50422",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50423",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50426",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent network.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00558,
            "epssPercentile": 0.44441,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50429",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network.",
            "score": 8.2,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01069,
            "epssPercentile": 0.62606,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50430",
            "title": "Windows Push Notification Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39648,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50431",
            "title": "Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability",
            "summary": "Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39648,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50432",
            "title": "Window Virtual Filtering Platform (VFP) Denial of Service Vulnerability",
            "summary": "Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized attacker to deny service over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00953,
            "epssPercentile": 0.59049,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50433",
            "title": "Windows Media Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Media allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50434",
            "title": "Windows Push Notification Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50435",
            "title": "Windows Overlay Filter Elevation of Privilege Vulnerability",
            "summary": "Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50437",
            "title": "Windows DWM Core Library Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50439",
            "title": "Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53953,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50441",
            "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
            "summary": "Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.2611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50442",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39646,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50444",
            "title": "Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00778,
            "epssPercentile": 0.53532,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50445",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58032,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50447",
            "title": "Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59787,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50448",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38799,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50449",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18082,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50450",
            "title": "Windows Network Connections Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10166,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50451",
            "title": "Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00307,
            "epssPercentile": 0.23134,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50452",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0036,
            "epssPercentile": 0.29103,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50453",
            "title": "Windows USB Audio Class Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0051,
            "epssPercentile": 0.41673,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50455",
            "title": "Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33743,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50456",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39646,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50459",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22679,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50460",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00542,
            "epssPercentile": 0.4363,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50461",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38801,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50462",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00457,
            "epssPercentile": 0.38194,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50463",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01027,
            "epssPercentile": 0.61357,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50469",
            "title": "Windows Projected File System Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows Projected File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0037,
            "epssPercentile": 0.30149,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50470",
            "title": "Windows Network Policy Server SNMP Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01027,
            "epssPercentile": 0.61358,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50471",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38793,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50473",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39644,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50474",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.54859,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50475",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.00375,
            "epssPercentile": 0.30678,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Medium technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50476",
            "title": "Windows Network Connections Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Windows allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20051,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50477",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.261,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50478",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26097,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50479",
            "title": "Windows USB Hub Driver Elevation of Privilege Vulnerability",
            "summary": "Untrusted pointer dereference in Windows USB Hub Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26097,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50482",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29001,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50484",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26112,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50485",
            "title": "Windows Hyper-V Denial of Service Vulnerability",
            "summary": "Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.",
            "score": 4.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00656,
            "epssPercentile": 0.49112,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50489",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50490",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20054,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50491",
            "title": "Code Integrity DLL (ci.dll) Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20054,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50492",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36764,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50493",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26098,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50494",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26098,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50495",
            "title": "DNS Client Tampering Vulnerability",
            "summary": "Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00302,
            "epssPercentile": 0.22534,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50496",
            "title": "Windows Network Policy Server SNMP Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50497",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58032,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50498",
            "title": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
            "summary": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00363,
            "epssPercentile": 0.29377,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50499",
            "title": "Windows Print Spooler Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50500",
            "title": "Windows Netlogon Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00742,
            "epssPercentile": 0.52348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50502",
            "title": "Windows Event Logging Service Remote Code Execution Vulnerability",
            "summary": "Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00654,
            "epssPercentile": 0.49042,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50504",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.5803,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50505",
            "title": "Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00742,
            "epssPercentile": 0.52348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50518",
            "title": "Windows DHCP Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59786,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50647",
            "title": "Active Directory Federation Server Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50655",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38797,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50661",
            "title": "Windows BitLocker Security Feature Bypass Vulnerability",
            "summary": "Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00481,
            "epssPercentile": 0.39822,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50666",
            "title": "Windows Remote Access Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.5779,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50667",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11651,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50668",
            "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36764,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50669",
            "title": "Windows Telephony Server Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.1017,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50670",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26096,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50672",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10166,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50673",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.1165,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50680",
            "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally.",
            "score": 8.2,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00338,
            "epssPercentile": 0.26665,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50681",
            "title": "Windows Secure Channel Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39645,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50682",
            "title": "Active Directory Denial of Service Vulnerability",
            "summary": "Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58293,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50683",
            "title": "Windows DHCP Client Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00576,
            "epssPercentile": 0.45358,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50684",
            "title": "Active Directory Federation Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Active Directory Federation Services (AD FS) allows an authorized attacker to perform spoofing over a network.",
            "score": 4.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00395,
            "epssPercentile": 0.32825,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50685",
            "title": "Windows DHCP Server Remote Code Execution Vulnerability",
            "summary": "Double free in Windows DHCP Server allows an authorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00663,
            "epssPercentile": 0.49414,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50686",
            "title": "Windows OLE Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00707,
            "epssPercentile": 0.5113,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50688",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20053,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50689",
            "title": "Windows Clipboard Server Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17026,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50690",
            "title": "Windows SMB Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50692",
            "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.261,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50694",
            "title": "Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53953,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50695",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65468,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50696",
            "title": "Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50697",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00395,
            "epssPercentile": 0.32743,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54107",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11651,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54109",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54112",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10171,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54114",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54115",
            "title": "Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26115,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54119",
            "title": "Windows Active Directory Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54121",
            "title": "Active Directory Certificate Services Elevation of Privilege Vulnerability",
            "summary": "Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01788,
            "epssPercentile": 0.76867,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54122",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00364,
            "epssPercentile": 0.29518,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54124",
            "title": "Windows Terminal Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.388,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54125",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17027,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54126",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58034,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54127",
            "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00305,
            "epssPercentile": 0.22804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54128",
            "title": "Windows DHCP Client Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00364,
            "epssPercentile": 0.29519,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54129",
            "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20054,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54982",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00535,
            "epssPercentile": 0.43236,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54983",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65471,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54986",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26113,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54987",
            "title": "Windows Overlay Filter Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54989",
            "title": "Quality Windows Audio/Video Experience (QWAVE) Elevation of Privilege Vulnerability",
            "summary": "Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20052,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54992",
            "title": "Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00337,
            "epssPercentile": 0.26479,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54993",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38795,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54995",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53953,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54997",
            "title": "Windows SMB Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54999",
            "title": "Windows TCP/IP Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0041,
            "epssPercentile": 0.34281,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55001",
            "title": "Active Directory Domain Services Elevation of Privilege Vulnerability",
            "summary": "Improper certificate validation in Windows Active Directory allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.2211,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55003",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55004",
            "title": "Windows Print Configuration Elevation of Privilege Vulnerability",
            "summary": "Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55144",
            "title": "Windows Cryptography API: Next Generation (CNG) Tampering Vulnerability",
            "summary": "Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00225,
            "epssPercentile": 0.13158,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56155",
            "title": "Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability",
            "summary": "Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2026-07-14.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00346,
            "epssPercentile": 0.27582,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2026-07-28 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56159",
            "title": "DHCP Server Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59787,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56168",
            "title": "Windows SMB Server Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01138,
            "epssPercentile": 0.64469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56173",
            "title": "Windows WebView Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18078,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56175",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26112,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56176",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26112,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56182",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26112,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56184",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39643,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56186",
            "title": "Windows Secure Channel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01106,
            "epssPercentile": 0.63644,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56188",
            "title": "Windows Server Network driver Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00607,
            "epssPercentile": 0.46852,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56189",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00393,
            "epssPercentile": 0.32499,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56190",
            "title": "Remote Desktop Protocol Remote Code Execution Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59787,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56194",
            "title": "Windows NFS Server Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.5779,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56643",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56644",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56647",
            "title": "Windows Remote Access Service Infrastructure Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.57789,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56648",
            "title": "Windows NFS Server Elevation of Privilege Vulnerability",
            "summary": "Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00509,
            "epssPercentile": 0.41581,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56649",
            "title": "Windows Network File System Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File System allows an unauthorized attacker to execute code over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00699,
            "epssPercentile": 0.50808,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56650",
            "title": "Windows Network File System Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57083",
            "title": "Windows Media Photo Codec Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.4355,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57084",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.43549,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57085",
            "title": "Windows Print Spooler Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0037,
            "epssPercentile": 0.30143,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57087",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53969,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57088",
            "title": "Extensible Storage Engine (ESENT) Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Extensible Storage Engine (ESENT) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57089",
            "title": "Windows SMB Server Network Transport Driver (srvnet.sys) Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00665,
            "epssPercentile": 0.49498,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57090",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.54858,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57091",
            "title": "Windows File History Service Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows File History Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57092",
            "title": "Microsoft Windows VMSwitch Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.",
            "score": 9.9,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.57791,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57093",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20053,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57094",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.54859,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57095",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00489,
            "epssPercentile": 0.40353,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57096",
            "title": "Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57097",
            "title": "Microsoft XML Security Feature Bypass Vulnerability",
            "summary": "Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack.",
            "score": 6.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00503,
            "epssPercentile": 0.41172,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57976",
            "title": "Windows Active Directory Domain Services Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01138,
            "epssPercentile": 0.64468,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57979",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58034,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57982",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00995,
            "epssPercentile": 0.60375,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58526",
            "title": "Windows Storage Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Storage allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11648,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58527",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.1165,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58528",
            "title": "Windows USB Audio Class Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00524,
            "epssPercentile": 0.42584,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58530",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00363,
            "epssPercentile": 0.29377,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58531",
            "title": "Windows SMB Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00509,
            "epssPercentile": 0.41581,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58532",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.261,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58533",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58033,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58534",
            "title": "Windows Input Method Editor (IME) Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26095,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58535",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58536",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26095,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58538",
            "title": "Windows Bluetooth Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26101,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58539",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58033,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58540",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58541",
            "title": "Microsoft DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26102,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58545",
            "title": "Windows Kernel Security Feature Bypass Vulnerability",
            "summary": "Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0035,
            "epssPercentile": 0.27951,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58546",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58033,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58547",
            "title": "Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00407,
            "epssPercentile": 0.33974,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58594",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.5486,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58601",
            "title": "Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability",
            "summary": "Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26102,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58608",
            "title": "Windows Print Spooler Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00569,
            "epssPercentile": 0.45031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58609",
            "title": "Windows Graphics Component Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38794,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58610",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38797,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58613",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.00377,
            "epssPercentile": 0.30833,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58614",
            "title": "Windows Kernel Security Feature Bypass Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33743,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58619",
            "title": "Windows Sensor Data Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.1808,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58626",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.57789,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58627",
            "title": "Windows DHCP Server Denial of Service Vulnerability",
            "summary": "Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58628",
            "title": "Windows Wireless Network Manager Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10171,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58629",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.1808,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58632",
            "title": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26101,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58635",
            "title": "Windows Narrator Braille Elevation of Privilege Vulnerability",
            "summary": "Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00322,
            "epssPercentile": 0.24873,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58637",
            "title": "Windows Client-Side Caching Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18082,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58638",
            "title": "Windows Boot Loader Security Feature Bypass Vulnerability",
            "summary": "Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.",
            "score": 6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00235,
            "epssPercentile": 0.14327,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58640",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29001,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Exploitation reported by the vendor source",
        "max_cvss": 9.9,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-57092",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-windows-kb5101649",
      "slug": "microsoft-2026-07-windows-kb5101649",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5101649",
      "title": "Deploy Microsoft Windows security update KB5101649",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5101649",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Windows 11 Version 26H1 for ARM64-based Systems, Windows 11 version 26H1 for x64-based Systems",
      "platform": "Windows",
      "release_version": "10.0.28000.2525",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 381 linked CVEs for Windows 11 Version 26H1 for ARM64-based Systems, Windows 11 version 26H1 for x64-based Systems. Microsoft marks CVE-2026-50661 as publicly disclosed, without that disclosure alone changing the BlackTree action window.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 381,
        "ids": [
          "CVE-2026-33842",
          "CVE-2026-34328",
          "CVE-2026-34346",
          "CVE-2026-34348",
          "CVE-2026-34349",
          "CVE-2026-40378",
          "CVE-2026-40400",
          "CVE-2026-40422",
          "CVE-2026-41087",
          "CVE-2026-42900",
          "CVE-2026-42975",
          "CVE-2026-42982",
          "CVE-2026-42990",
          "CVE-2026-44800",
          "CVE-2026-44806",
          "CVE-2026-48571",
          "CVE-2026-48572",
          "CVE-2026-49162",
          "CVE-2026-49164",
          "CVE-2026-49165",
          "CVE-2026-49166",
          "CVE-2026-49167",
          "CVE-2026-49168",
          "CVE-2026-49170",
          "CVE-2026-49171",
          "CVE-2026-49172",
          "CVE-2026-49173",
          "CVE-2026-49174",
          "CVE-2026-49175",
          "CVE-2026-49176",
          "CVE-2026-49177",
          "CVE-2026-49178",
          "CVE-2026-49180",
          "CVE-2026-49183",
          "CVE-2026-49184",
          "CVE-2026-49783",
          "CVE-2026-49784",
          "CVE-2026-49787",
          "CVE-2026-49788",
          "CVE-2026-49789",
          "CVE-2026-49790",
          "CVE-2026-49791",
          "CVE-2026-49792",
          "CVE-2026-49793",
          "CVE-2026-49794",
          "CVE-2026-49795",
          "CVE-2026-49796",
          "CVE-2026-49797",
          "CVE-2026-49798",
          "CVE-2026-49799",
          "CVE-2026-49800",
          "CVE-2026-49801",
          "CVE-2026-49802",
          "CVE-2026-49803",
          "CVE-2026-49805",
          "CVE-2026-49806",
          "CVE-2026-49807",
          "CVE-2026-49808",
          "CVE-2026-50293",
          "CVE-2026-50294",
          "CVE-2026-50295",
          "CVE-2026-50296",
          "CVE-2026-50297",
          "CVE-2026-50298",
          "CVE-2026-50299",
          "CVE-2026-50300",
          "CVE-2026-50302",
          "CVE-2026-50303",
          "CVE-2026-50305",
          "CVE-2026-50306",
          "CVE-2026-50307",
          "CVE-2026-50308",
          "CVE-2026-50309",
          "CVE-2026-50310",
          "CVE-2026-50311",
          "CVE-2026-50312",
          "CVE-2026-50313",
          "CVE-2026-50315",
          "CVE-2026-50316",
          "CVE-2026-50317",
          "CVE-2026-50318",
          "CVE-2026-50321",
          "CVE-2026-50322",
          "CVE-2026-50323",
          "CVE-2026-50325",
          "CVE-2026-50326",
          "CVE-2026-50327",
          "CVE-2026-50329",
          "CVE-2026-50330",
          "CVE-2026-50331",
          "CVE-2026-50332",
          "CVE-2026-50333",
          "CVE-2026-50334",
          "CVE-2026-50335",
          "CVE-2026-50336",
          "CVE-2026-50337",
          "CVE-2026-50339",
          "CVE-2026-50340",
          "CVE-2026-50341",
          "CVE-2026-50342",
          "CVE-2026-50343",
          "CVE-2026-50344",
          "CVE-2026-50345",
          "CVE-2026-50346",
          "CVE-2026-50347",
          "CVE-2026-50348",
          "CVE-2026-50350",
          "CVE-2026-50351",
          "CVE-2026-50352",
          "CVE-2026-50353",
          "CVE-2026-50354",
          "CVE-2026-50356",
          "CVE-2026-50357",
          "CVE-2026-50358",
          "CVE-2026-50359",
          "CVE-2026-50360",
          "CVE-2026-50361",
          "CVE-2026-50362",
          "CVE-2026-50363",
          "CVE-2026-50364",
          "CVE-2026-50365",
          "CVE-2026-50366",
          "CVE-2026-50367",
          "CVE-2026-50369",
          "CVE-2026-50371",
          "CVE-2026-50372",
          "CVE-2026-50373",
          "CVE-2026-50374",
          "CVE-2026-50375",
          "CVE-2026-50376",
          "CVE-2026-50377",
          "CVE-2026-50378",
          "CVE-2026-50379",
          "CVE-2026-50380",
          "CVE-2026-50381",
          "CVE-2026-50382",
          "CVE-2026-50383",
          "CVE-2026-50384",
          "CVE-2026-50385",
          "CVE-2026-50386",
          "CVE-2026-50387",
          "CVE-2026-50388",
          "CVE-2026-50389",
          "CVE-2026-50390",
          "CVE-2026-50391",
          "CVE-2026-50392",
          "CVE-2026-50393",
          "CVE-2026-50394",
          "CVE-2026-50396",
          "CVE-2026-50397",
          "CVE-2026-50398",
          "CVE-2026-50399",
          "CVE-2026-50400",
          "CVE-2026-50401",
          "CVE-2026-50402",
          "CVE-2026-50403",
          "CVE-2026-50404",
          "CVE-2026-50405",
          "CVE-2026-50406",
          "CVE-2026-50407",
          "CVE-2026-50409",
          "CVE-2026-50410",
          "CVE-2026-50411",
          "CVE-2026-50412",
          "CVE-2026-50413",
          "CVE-2026-50414",
          "CVE-2026-50415",
          "CVE-2026-50416",
          "CVE-2026-50417",
          "CVE-2026-50418",
          "CVE-2026-50419",
          "CVE-2026-50420",
          "CVE-2026-50421",
          "CVE-2026-50422",
          "CVE-2026-50423",
          "CVE-2026-50424",
          "CVE-2026-50425",
          "CVE-2026-50427",
          "CVE-2026-50428",
          "CVE-2026-50429",
          "CVE-2026-50430",
          "CVE-2026-50431",
          "CVE-2026-50432",
          "CVE-2026-50433",
          "CVE-2026-50434",
          "CVE-2026-50435",
          "CVE-2026-50436",
          "CVE-2026-50437",
          "CVE-2026-50439",
          "CVE-2026-50440",
          "CVE-2026-50441",
          "CVE-2026-50442",
          "CVE-2026-50445",
          "CVE-2026-50447",
          "CVE-2026-50448",
          "CVE-2026-50449",
          "CVE-2026-50450",
          "CVE-2026-50451",
          "CVE-2026-50452",
          "CVE-2026-50453",
          "CVE-2026-50454",
          "CVE-2026-50455",
          "CVE-2026-50456",
          "CVE-2026-50457",
          "CVE-2026-50458",
          "CVE-2026-50459",
          "CVE-2026-50460",
          "CVE-2026-50461",
          "CVE-2026-50462",
          "CVE-2026-50463",
          "CVE-2026-50465",
          "CVE-2026-50466",
          "CVE-2026-50469",
          "CVE-2026-50470",
          "CVE-2026-50471",
          "CVE-2026-50473",
          "CVE-2026-50474",
          "CVE-2026-50475",
          "CVE-2026-50476",
          "CVE-2026-50477",
          "CVE-2026-50478",
          "CVE-2026-50482",
          "CVE-2026-50483",
          "CVE-2026-50484",
          "CVE-2026-50485",
          "CVE-2026-50486",
          "CVE-2026-50487",
          "CVE-2026-50489",
          "CVE-2026-50490",
          "CVE-2026-50491",
          "CVE-2026-50492",
          "CVE-2026-50493",
          "CVE-2026-50494",
          "CVE-2026-50495",
          "CVE-2026-50496",
          "CVE-2026-50497",
          "CVE-2026-50498",
          "CVE-2026-50499",
          "CVE-2026-50500",
          "CVE-2026-50501",
          "CVE-2026-50502",
          "CVE-2026-50503",
          "CVE-2026-50504",
          "CVE-2026-50505",
          "CVE-2026-50509",
          "CVE-2026-50647",
          "CVE-2026-50655",
          "CVE-2026-50661",
          "CVE-2026-50666",
          "CVE-2026-50667",
          "CVE-2026-50668",
          "CVE-2026-50669",
          "CVE-2026-50670",
          "CVE-2026-50672",
          "CVE-2026-50673",
          "CVE-2026-50674",
          "CVE-2026-50676",
          "CVE-2026-50677",
          "CVE-2026-50679",
          "CVE-2026-50680",
          "CVE-2026-50681",
          "CVE-2026-50682",
          "CVE-2026-50686",
          "CVE-2026-50687",
          "CVE-2026-50688",
          "CVE-2026-50689",
          "CVE-2026-50690",
          "CVE-2026-50692",
          "CVE-2026-50694",
          "CVE-2026-50695",
          "CVE-2026-50696",
          "CVE-2026-50697",
          "CVE-2026-54107",
          "CVE-2026-54109",
          "CVE-2026-54111",
          "CVE-2026-54112",
          "CVE-2026-54114",
          "CVE-2026-54115",
          "CVE-2026-54119",
          "CVE-2026-54122",
          "CVE-2026-54124",
          "CVE-2026-54125",
          "CVE-2026-54126",
          "CVE-2026-54127",
          "CVE-2026-54128",
          "CVE-2026-54129",
          "CVE-2026-54132",
          "CVE-2026-54982",
          "CVE-2026-54983",
          "CVE-2026-54986",
          "CVE-2026-54987",
          "CVE-2026-54989",
          "CVE-2026-54990",
          "CVE-2026-54991",
          "CVE-2026-54992",
          "CVE-2026-54993",
          "CVE-2026-54995",
          "CVE-2026-54996",
          "CVE-2026-54997",
          "CVE-2026-54999",
          "CVE-2026-55000",
          "CVE-2026-55003",
          "CVE-2026-55004",
          "CVE-2026-55144",
          "CVE-2026-56168",
          "CVE-2026-56173",
          "CVE-2026-56175",
          "CVE-2026-56176",
          "CVE-2026-56181",
          "CVE-2026-56182",
          "CVE-2026-56183",
          "CVE-2026-56184",
          "CVE-2026-56186",
          "CVE-2026-56187",
          "CVE-2026-56188",
          "CVE-2026-56189",
          "CVE-2026-56190",
          "CVE-2026-56194",
          "CVE-2026-56643",
          "CVE-2026-56644",
          "CVE-2026-56647",
          "CVE-2026-56648",
          "CVE-2026-56649",
          "CVE-2026-56650",
          "CVE-2026-57083",
          "CVE-2026-57084",
          "CVE-2026-57085",
          "CVE-2026-57087",
          "CVE-2026-57089",
          "CVE-2026-57090",
          "CVE-2026-57091",
          "CVE-2026-57092",
          "CVE-2026-57093",
          "CVE-2026-57094",
          "CVE-2026-57095",
          "CVE-2026-57096",
          "CVE-2026-57097",
          "CVE-2026-57976",
          "CVE-2026-57979",
          "CVE-2026-57982",
          "CVE-2026-58526",
          "CVE-2026-58527",
          "CVE-2026-58528",
          "CVE-2026-58529",
          "CVE-2026-58530",
          "CVE-2026-58531",
          "CVE-2026-58532",
          "CVE-2026-58533",
          "CVE-2026-58534",
          "CVE-2026-58535",
          "CVE-2026-58536",
          "CVE-2026-58537",
          "CVE-2026-58538",
          "CVE-2026-58539",
          "CVE-2026-58540",
          "CVE-2026-58541",
          "CVE-2026-58542",
          "CVE-2026-58543",
          "CVE-2026-58544",
          "CVE-2026-58545",
          "CVE-2026-58546",
          "CVE-2026-58547",
          "CVE-2026-58594",
          "CVE-2026-58601",
          "CVE-2026-58602",
          "CVE-2026-58608",
          "CVE-2026-58609",
          "CVE-2026-58610",
          "CVE-2026-58613",
          "CVE-2026-58614",
          "CVE-2026-58619",
          "CVE-2026-58626",
          "CVE-2026-58628",
          "CVE-2026-58629",
          "CVE-2026-58632",
          "CVE-2026-58633",
          "CVE-2026-58634",
          "CVE-2026-58635",
          "CVE-2026-58637",
          "CVE-2026-58638",
          "CVE-2026-58640"
        ],
        "details": [
          {
            "id": "CVE-2026-33842",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39646,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-34328",
            "title": "Windows Audio Service Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39644,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-34346",
            "title": "Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability",
            "summary": "Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0027,
            "epssPercentile": 0.18916,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-34348",
            "title": "Windows Event Logging Service Information Disclosure Vulnerability",
            "summary": "Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00907,
            "epssPercentile": 0.57588,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-34349",
            "title": "Windows Media Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39645,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-40378",
            "title": "Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability",
            "summary": "Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65473,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-40400",
            "title": "Windows PowerShell Remote Code Execution Vulnerability",
            "summary": "Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00868,
            "epssPercentile": 0.56393,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-40422",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33743,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-41087",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39643,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-42900",
            "title": "Microsoft Windows App Store Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00542,
            "epssPercentile": 0.43631,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-42975",
            "title": "Windows Bluetooth Port Driver Remote Code Execution",
            "summary": "Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00536,
            "epssPercentile": 0.43257,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-42982",
            "title": "Windows Secure Kernel Mode Elevation of Privilege Vulnerability",
            "summary": "Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26114,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-42990",
            "title": "SQL Server ODBC driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59786,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-44800",
            "title": "Windows Push Notifications Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.1017,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-44806",
            "title": "Windows Secure Channel Denial of Service Vulnerability",
            "summary": "Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65471,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48571",
            "title": "Windows App Package Installer Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18081,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48572",
            "title": "Windows App Package Installer Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10166,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49162",
            "title": "Microsoft Brokering File System Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18081,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49164",
            "title": "Windows Active Directory Domain Services Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53952,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49165",
            "title": "Microsoft Windows App Store Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00338,
            "epssPercentile": 0.26611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49166",
            "title": "Windows Print Configuration Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26113,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49167",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 4.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0035,
            "epssPercentile": 0.28037,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49168",
            "title": "Storage Spaces Direct Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36763,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49170",
            "title": "Windows StateRepository API Server file Elevation of Privilege Vulnerability",
            "summary": "Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.2211,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49171",
            "title": "Windows Speech Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.003,
            "epssPercentile": 0.22345,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49172",
            "title": "Windows FTP Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59785,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49173",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26113,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49174",
            "title": "DNS Client Tampering Vulnerability",
            "summary": "Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0027,
            "epssPercentile": 0.18886,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49175",
            "title": "Windows DNS Client Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26114,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49176",
            "title": "Windows WalletService Elevation of Privilege Vulnerability",
            "summary": "Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00471,
            "epssPercentile": 0.39116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49177",
            "title": "Windows TCP/IP Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00443,
            "epssPercentile": 0.37172,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49178",
            "title": "Windows Active Directory Domain Services Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.57789,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49180",
            "title": "Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00444,
            "epssPercentile": 0.37219,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49183",
            "title": "Windows Clipboard Server Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10168,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49184",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00337,
            "epssPercentile": 0.26479,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49783",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26114,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49784",
            "title": "Microsoft Windows App Store Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10169,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49787",
            "title": "HTTP.sys Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65471,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49788",
            "title": "HTTP/2 Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49789",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29002,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49790",
            "title": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
            "summary": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29001,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49791",
            "title": "Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0038,
            "epssPercentile": 0.31138,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49792",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26115,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49793",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26113,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49794",
            "title": "Windows USB Audio Class Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00468,
            "epssPercentile": 0.3893,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49795",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26115,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49796",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49797",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38802,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49798",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.",
            "score": 9.3,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00364,
            "epssPercentile": 0.29518,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49799",
            "title": "Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability",
            "summary": "Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01138,
            "epssPercentile": 0.64468,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49800",
            "title": "Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26115,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49801",
            "title": "Windows SMB Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33744,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49802",
            "title": "Windows USB Print Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10169,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49803",
            "title": "Windows AppX Deployment Extensions Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.1017,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49805",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00236,
            "epssPercentile": 0.14488,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49806",
            "title": "Windows USB Print Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10171,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49807",
            "title": "Windows DirectX Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows DirectX allows an unauthorized attacker to disclose information locally.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00506,
            "epssPercentile": 0.41392,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49808",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10167,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50293",
            "title": "Windows Internal Task Bar Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Internal Task Bar allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50294",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized attacker to disclose information locally.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00506,
            "epssPercentile": 0.41392,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50295",
            "title": "Windows Zero Trust DNS Security Feature Bypass Vulnerability",
            "summary": "Improper privilege management in Microsoft Windows DNS allows an authorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00302,
            "epssPercentile": 0.22534,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50296",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Graphics Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18079,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50297",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00236,
            "epssPercentile": 0.14488,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50298",
            "title": "Windows Spaceport.sys Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36765,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50299",
            "title": "Windows Storage Spaces Direct Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36764,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50300",
            "title": "Windows DWM Core Library Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50302",
            "title": "Windows Cryptographic Services Security Feature Bypass Vulnerability",
            "summary": "Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 4.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00334,
            "epssPercentile": 0.2625,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50303",
            "title": "Windows Key Guard Security Feature Bypass Vulnerability",
            "summary": "Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0027,
            "epssPercentile": 0.18916,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50305",
            "title": "Microsoft Brokering File System Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17026,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50306",
            "title": "Windows TCP/IP Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26104,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50307",
            "title": "Windows TCP/IP Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20052,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50308",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38802,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50309",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26104,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50310",
            "title": "Windows Human Interface Device Information Disclosure Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information locally.",
            "score": 4.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23556,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50311",
            "title": "Windows Server Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50312",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 4.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0035,
            "epssPercentile": 0.28037,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50313",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38794,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50315",
            "title": "Windows Image Acquisition Elevation of Privilege Vulnerability",
            "summary": "Null pointer dereference in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26103,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50316",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39648,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50317",
            "title": "Windows Operating Systems Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Operating Systems allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11648,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50318",
            "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26103,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50321",
            "title": "Windows USB Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11649,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50322",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10167,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50323",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18079,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50325",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00236,
            "epssPercentile": 0.14488,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50326",
            "title": "Windows Unified Consent System Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Unified Consent System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50327",
            "title": "Windows Media Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50329",
            "title": "Microsoft DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50330",
            "title": "Windows Remote Desktop Client Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01252,
            "epssPercentile": 0.6748,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50331",
            "title": "Windows Application Model Core API Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Application Model allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50332",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50333",
            "title": "Windows Spaceport.sys Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50334",
            "title": "Windows Push Notification Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Notification allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39645,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50335",
            "title": "Windows Operating Systems Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50336",
            "title": "Windows Media Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Media allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26103,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50337",
            "title": "Windows Notification Elevation of Privilege Vulnerability",
            "summary": "Incorrect type conversion or cast in Windows Notification allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26104,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50339",
            "title": "Windows Push Notification Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39645,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50340",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Runtime allows an authorized attacker to elevate privileges over a network.",
            "score": 8.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00742,
            "epssPercentile": 0.52348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50341",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33741,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50342",
            "title": "Windows MIDI Service Module Elevation of Privileges Vulnerability",
            "summary": "Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50343",
            "title": "Microsoft Install Service Elevation of Privilege Vulnerability",
            "summary": "Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50344",
            "title": "Windows OLE Elevation of Privilege Vulnerability",
            "summary": "Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50345",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10168,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50346",
            "title": "Netlogon RPC Elevation of Privilege Vulnerability",
            "summary": "Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50347",
            "title": "Windows Data.dll Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38792,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50348",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0036,
            "epssPercentile": 0.29103,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50350",
            "title": "Windows Trusted Runtime Interface Driver Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39646,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50351",
            "title": "Windows Audio Compression Manager (ACM) Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50352",
            "title": "Windows Cryptographic Services Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50353",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50354",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26129,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50356",
            "title": "Microsoft Windows App Store Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10168,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50357",
            "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50358",
            "title": "Windows Media Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Media allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20051,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50359",
            "title": "Microsoft XML Core Services Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20051,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50360",
            "title": "Windows SMB Server Elevation of Privilege Vulnerability",
            "summary": "Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00778,
            "epssPercentile": 0.53532,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50361",
            "title": "Microsoft Brokering File System Elevation of Privilege Vulnerability",
            "summary": "Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17027,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50362",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38801,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50363",
            "title": "Windows Push Notifications Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26102,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50364",
            "title": "Windows Backup Service Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows Server Backup allows an authorized attacker to elevate privileges locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00469,
            "epssPercentile": 0.38948,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50365",
            "title": "Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability",
            "summary": "Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00542,
            "epssPercentile": 0.43604,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50366",
            "title": "Windows Active Directory Domain Services Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01138,
            "epssPercentile": 0.64468,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50367",
            "title": "Windows Sensor Data Service Elevation of Privilege Vulnerability",
            "summary": "Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26103,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50369",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00701,
            "epssPercentile": 0.50891,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50371",
            "title": "Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows LUAFV allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10167,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50372",
            "title": "Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability",
            "summary": "Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18081,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50373",
            "title": "Windows Search Service Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50374",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00347,
            "epssPercentile": 0.27656,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50375",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DirectX allows an authorized attacker to elevate privileges locally.",
            "score": 6.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00295,
            "epssPercentile": 0.21728,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50376",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50377",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00409,
            "epssPercentile": 0.34158,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50378",
            "title": "Windows Key Guard Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Key Guard allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11649,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50379",
            "title": "Windows Media Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00509,
            "epssPercentile": 0.41581,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50380",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.",
            "score": 9.6,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.54859,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50381",
            "title": "Composite Image File System driver (cimfs.sys) Information Disclosure Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Composite Image File System Driver allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33744,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50382",
            "title": "DirectX Graphics Kernel Remote Code Execution Vulnerability",
            "summary": "Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50383",
            "title": "Windows Print Spooler Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33741,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50384",
            "title": "Windows Clip Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clip Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10168,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50385",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17027,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50386",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38791,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50387",
            "title": "Windows GDI Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26111,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50388",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38797,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50389",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39644,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50390",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20053,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50391",
            "title": "Windows Group Policy Elevation of Privilege Vulnerability",
            "summary": "Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.2211,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50392",
            "title": "Windows Secure Kernel Mode Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18082,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50393",
            "title": "Windows Kernel-Mode Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20052,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50394",
            "title": "Windows Media Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39643,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50396",
            "title": "Windows Kernel-Mode Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20051,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50397",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18081,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50398",
            "title": "Windows Media Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00569,
            "epssPercentile": 0.4503,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50399",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26111,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50400",
            "title": "Windows App Package Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.2611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50401",
            "title": "Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33744,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50402",
            "title": "NTFS Elevation of Privilege Vulnerability",
            "summary": "Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.2611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50403",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10165,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50404",
            "title": "Windows Media Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10166,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50405",
            "title": "Windows Filtering Platform Elevation of Privilege Vulnerability",
            "summary": "Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50406",
            "title": "Windows Backup Engine Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Backup Engine allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20052,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50407",
            "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50409",
            "title": "Windows Overlay Filter Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Overlay Filter allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50410",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18079,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50411",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50412",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50413",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26098,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50414",
            "title": "Windows Media Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00569,
            "epssPercentile": 0.45031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50415",
            "title": "Windows Media Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Media allows an unauthorized attacker to disclose information over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0086,
            "epssPercentile": 0.56162,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50416",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 3.3,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00458,
            "epssPercentile": 0.38212,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50417",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26111,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50418",
            "title": "Windows System Secure Feature Bypass Vulnerability",
            "summary": "Improper access control in Windows System allows an unauthorized attacker to bypass a security feature locally.",
            "score": 5.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00266,
            "epssPercentile": 0.18272,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50419",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.",
            "score": 3.3,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00458,
            "epssPercentile": 0.38211,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50420",
            "title": "HTTP.sys Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to disclose information locally.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00408,
            "epssPercentile": 0.34085,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50421",
            "title": "Windows Connected User Experiences and Telemetry Elevation of Privilege Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.2611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50422",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50423",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50424",
            "title": "Windows Domain Controller Denial of Service Vulnerability",
            "summary": "Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65473,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50425",
            "title": "Windows Internal System User Profile Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Internal System User Profile allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50427",
            "title": "Content Delivery Manager Elevation of Privilege Vulnerability",
            "summary": "Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17026,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50428",
            "title": "Windows Container Isolation FS Filter Driver (unionfs.sys) Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00412,
            "epssPercentile": 0.344,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50429",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network.",
            "score": 8.2,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01069,
            "epssPercentile": 0.62606,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50430",
            "title": "Windows Push Notification Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39648,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50431",
            "title": "Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability",
            "summary": "Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39648,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50432",
            "title": "Window Virtual Filtering Platform (VFP) Denial of Service Vulnerability",
            "summary": "Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized attacker to deny service over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00953,
            "epssPercentile": 0.59049,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50433",
            "title": "Windows Media Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Media allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50434",
            "title": "Windows Push Notification Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50435",
            "title": "Windows Overlay Filter Elevation of Privilege Vulnerability",
            "summary": "Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50436",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50437",
            "title": "Windows DWM Core Library Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50439",
            "title": "Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53953,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50440",
            "title": "Windows Audio Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Audio Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11649,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50441",
            "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
            "summary": "Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.2611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50442",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39646,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50445",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58032,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50447",
            "title": "Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59787,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50448",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38799,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50449",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18082,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50450",
            "title": "Windows Network Connections Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10166,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50451",
            "title": "Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00307,
            "epssPercentile": 0.23134,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50452",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0036,
            "epssPercentile": 0.29103,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50453",
            "title": "Windows USB Audio Class Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0051,
            "epssPercentile": 0.41673,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50454",
            "title": "Windows User Interface Core Elevation of Privilege Vulnerability",
            "summary": "Relative path traversal in Windows User Interface Core allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0037,
            "epssPercentile": 0.30148,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50455",
            "title": "Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33743,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50456",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39646,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50457",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17027,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50458",
            "title": "Microsoft Brokering File System Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17025,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50459",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22679,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50460",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00542,
            "epssPercentile": 0.4363,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50461",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38801,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50462",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00457,
            "epssPercentile": 0.38194,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50463",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01027,
            "epssPercentile": 0.61357,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50465",
            "title": "Windows DNS Client Tampering Vulnerability",
            "summary": "Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50466",
            "title": "Microsoft Brokering File System Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Brokering File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26096,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50469",
            "title": "Windows Projected File System Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows Projected File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0037,
            "epssPercentile": 0.30149,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50470",
            "title": "Windows Network Policy Server SNMP Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01027,
            "epssPercentile": 0.61358,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50471",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38793,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50473",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39644,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50474",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.54859,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50475",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.00375,
            "epssPercentile": 0.30678,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Medium technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50476",
            "title": "Windows Network Connections Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Windows allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20051,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50477",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.261,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50478",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26097,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50482",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29001,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50483",
            "title": "Windows Graphics Component Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39643,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50484",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26112,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50485",
            "title": "Windows Hyper-V Denial of Service Vulnerability",
            "summary": "Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.",
            "score": 4.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00656,
            "epssPercentile": 0.49112,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50486",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26097,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50487",
            "title": "Windows DNS Client Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Windows DNS allows an unauthorized attacker to elevate privileges over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53953,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50489",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50490",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20054,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50491",
            "title": "Code Integrity DLL (ci.dll) Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20054,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50492",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36764,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50493",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26098,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50494",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26098,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50495",
            "title": "DNS Client Tampering Vulnerability",
            "summary": "Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00302,
            "epssPercentile": 0.22534,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50496",
            "title": "Windows Network Policy Server SNMP Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50497",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58032,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50498",
            "title": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
            "summary": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00363,
            "epssPercentile": 0.29377,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50499",
            "title": "Windows Print Spooler Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50500",
            "title": "Windows Netlogon Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00742,
            "epssPercentile": 0.52348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50501",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00363,
            "epssPercentile": 0.29377,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50502",
            "title": "Windows Event Logging Service Remote Code Execution Vulnerability",
            "summary": "Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00654,
            "epssPercentile": 0.49042,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50503",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10169,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50504",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.5803,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50505",
            "title": "Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00742,
            "epssPercentile": 0.52348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50509",
            "title": "Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability",
            "summary": "Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0353,
            "epssPercentile": 0.88474,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50647",
            "title": "Active Directory Federation Server Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50655",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38797,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50661",
            "title": "Windows BitLocker Security Feature Bypass Vulnerability",
            "summary": "Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00481,
            "epssPercentile": 0.39822,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50666",
            "title": "Windows Remote Access Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.5779,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50667",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11651,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50668",
            "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36764,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50669",
            "title": "Windows Telephony Server Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.1017,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50670",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26096,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50672",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10166,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50673",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.1165,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50674",
            "title": "Windows USB Print Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.2005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50676",
            "title": "Windows Media Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.1165,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50677",
            "title": "Windows Media Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Media allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17026,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50679",
            "title": "Windows Search Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26096,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50680",
            "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally.",
            "score": 8.2,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00338,
            "epssPercentile": 0.26665,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50681",
            "title": "Windows Secure Channel Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39645,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50682",
            "title": "Active Directory Denial of Service Vulnerability",
            "summary": "Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58293,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50686",
            "title": "Windows OLE Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00707,
            "epssPercentile": 0.5113,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50687",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26095,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50688",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20053,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50689",
            "title": "Windows Clipboard Server Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17026,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50690",
            "title": "Windows SMB Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50692",
            "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.261,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50694",
            "title": "Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53953,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50695",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65468,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50696",
            "title": "Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50697",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00395,
            "epssPercentile": 0.32743,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54107",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11651,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54109",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54111",
            "title": "Universal Print Management Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10165,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54112",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10171,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54114",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54115",
            "title": "Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26115,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54119",
            "title": "Windows Active Directory Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54122",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00364,
            "epssPercentile": 0.29518,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54124",
            "title": "Windows Terminal Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.388,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54125",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17027,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54126",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58034,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54127",
            "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00305,
            "epssPercentile": 0.22804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54128",
            "title": "Windows DHCP Client Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00364,
            "epssPercentile": 0.29519,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54129",
            "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20054,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54132",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36764,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54982",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00535,
            "epssPercentile": 0.43236,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54983",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65471,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54986",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26113,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54987",
            "title": "Windows Overlay Filter Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54989",
            "title": "Quality Windows Audio/Video Experience (QWAVE) Elevation of Privilege Vulnerability",
            "summary": "Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20052,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54990",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.54861,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54991",
            "title": "Windows USB Print Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11649,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54992",
            "title": "Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00337,
            "epssPercentile": 0.26479,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54993",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38795,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54995",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53953,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54996",
            "title": "Windows USB Print Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10171,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54997",
            "title": "Windows SMB Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54999",
            "title": "Windows TCP/IP Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0041,
            "epssPercentile": 0.34281,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55000",
            "title": "Windows USB Print Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00339,
            "epssPercentile": 0.26781,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55003",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55004",
            "title": "Windows Print Configuration Elevation of Privilege Vulnerability",
            "summary": "Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55144",
            "title": "Windows Cryptography API: Next Generation (CNG) Tampering Vulnerability",
            "summary": "Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00225,
            "epssPercentile": 0.13158,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56168",
            "title": "Windows SMB Server Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01138,
            "epssPercentile": 0.64469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56173",
            "title": "Windows WebView Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18078,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56175",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26112,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56176",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26112,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56181",
            "title": "Windows Network Address Translation (NAT) Spoofing Vulnerability",
            "summary": "Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.",
            "score": 8.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00276,
            "epssPercentile": 0.19734,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56182",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26112,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56183",
            "title": "Windows MIDI Service Module Elevation of Privileges Vulnerability",
            "summary": "Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18079,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56184",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39643,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56186",
            "title": "Windows Secure Channel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01106,
            "epssPercentile": 0.63644,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56187",
            "title": "Windows MIDI Service Module Elevation of Privileges Vulnerability",
            "summary": "Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20054,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56188",
            "title": "Windows Server Network driver Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00607,
            "epssPercentile": 0.46852,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56189",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00393,
            "epssPercentile": 0.32499,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56190",
            "title": "Remote Desktop Protocol Remote Code Execution Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59787,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56194",
            "title": "Windows NFS Server Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.5779,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56643",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56644",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56647",
            "title": "Windows Remote Access Service Infrastructure Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.57789,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56648",
            "title": "Windows NFS Server Elevation of Privilege Vulnerability",
            "summary": "Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00509,
            "epssPercentile": 0.41581,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56649",
            "title": "Windows Network File System Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File System allows an unauthorized attacker to execute code over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00699,
            "epssPercentile": 0.50808,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56650",
            "title": "Windows Network File System Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57083",
            "title": "Windows Media Photo Codec Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.4355,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57084",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.43549,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57085",
            "title": "Windows Print Spooler Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0037,
            "epssPercentile": 0.30143,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57087",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53969,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57089",
            "title": "Windows SMB Server Network Transport Driver (srvnet.sys) Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00665,
            "epssPercentile": 0.49498,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57090",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.54858,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57091",
            "title": "Windows File History Service Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows File History Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57092",
            "title": "Microsoft Windows VMSwitch Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.",
            "score": 9.9,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.57791,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57093",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20053,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57094",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.54859,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57095",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00489,
            "epssPercentile": 0.40353,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57096",
            "title": "Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57097",
            "title": "Microsoft XML Security Feature Bypass Vulnerability",
            "summary": "Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack.",
            "score": 6.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00503,
            "epssPercentile": 0.41172,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57976",
            "title": "Windows Active Directory Domain Services Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01138,
            "epssPercentile": 0.64468,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57979",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58034,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57982",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00995,
            "epssPercentile": 0.60375,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58526",
            "title": "Windows Storage Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Storage allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11648,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58527",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.1165,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58528",
            "title": "Windows USB Audio Class Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00524,
            "epssPercentile": 0.42584,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58529",
            "title": "Windows Active Directory Federation Services (ADFS) Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01036,
            "epssPercentile": 0.61645,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58530",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00363,
            "epssPercentile": 0.29377,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58531",
            "title": "Windows SMB Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00509,
            "epssPercentile": 0.41581,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58532",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.261,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58533",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58033,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58534",
            "title": "Windows Input Method Editor (IME) Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26095,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58535",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58536",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26095,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58537",
            "title": "Microsoft NAT Helper Components (ipnathlp.dll) Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft NAT Helper Components (ipnathlp.dll) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.261,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58538",
            "title": "Windows Bluetooth Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26101,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58539",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58033,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58540",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58541",
            "title": "Microsoft DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26102,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58542",
            "title": "Windows Media Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00363,
            "epssPercentile": 0.29376,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58543",
            "title": "Universal Print Management Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00244,
            "epssPercentile": 0.15497,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58544",
            "title": "Windows Management Services Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.1808,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58545",
            "title": "Windows Kernel Security Feature Bypass Vulnerability",
            "summary": "Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0035,
            "epssPercentile": 0.27951,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58546",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58033,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58547",
            "title": "Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00407,
            "epssPercentile": 0.33974,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58594",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.5486,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58601",
            "title": "Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability",
            "summary": "Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26102,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58602",
            "title": "Windows Kernel-Mode Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26102,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58608",
            "title": "Windows Print Spooler Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00569,
            "epssPercentile": 0.45031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58609",
            "title": "Windows Graphics Component Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38794,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58610",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38797,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58613",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.00377,
            "epssPercentile": 0.30833,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58614",
            "title": "Windows Kernel Security Feature Bypass Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33743,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58619",
            "title": "Windows Sensor Data Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.1808,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58626",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.57789,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58628",
            "title": "Windows Wireless Network Manager Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10171,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58629",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.1808,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58632",
            "title": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26101,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58633",
            "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
            "summary": "Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26101,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58634",
            "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
            "summary": "Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26096,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58635",
            "title": "Windows Narrator Braille Elevation of Privilege Vulnerability",
            "summary": "Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00322,
            "epssPercentile": 0.24873,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58637",
            "title": "Windows Client-Side Caching Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18082,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58638",
            "title": "Windows Boot Loader Security Feature Bypass Vulnerability",
            "summary": "Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.",
            "score": 6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00235,
            "epssPercentile": 0.14327,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58640",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29001,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.9,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-57092",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-windows-kb5101650",
      "slug": "microsoft-2026-07-windows-kb5101650",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5101650",
      "title": "Deploy Microsoft Windows security update KB5101650",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5101650",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "revised",
      "product": "Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows 11 Version 25H2 for ARM64-based Systems, plus 1 more",
      "platform": "Windows",
      "release_version": "10.0.26100.8875, 10.0.26200.8875",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 378 linked CVEs for Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows 11 Version 25H2 for ARM64-based Systems, plus 1 more. Microsoft marks CVE-2026-50661 as publicly disclosed, without that disclosure alone changing the BlackTree action window.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 378,
        "ids": [
          "CVE-2026-33842",
          "CVE-2026-34328",
          "CVE-2026-34346",
          "CVE-2026-34348",
          "CVE-2026-34349",
          "CVE-2026-40378",
          "CVE-2026-40400",
          "CVE-2026-40422",
          "CVE-2026-41087",
          "CVE-2026-42900",
          "CVE-2026-42975",
          "CVE-2026-42982",
          "CVE-2026-42990",
          "CVE-2026-44800",
          "CVE-2026-44806",
          "CVE-2026-48571",
          "CVE-2026-48572",
          "CVE-2026-49162",
          "CVE-2026-49164",
          "CVE-2026-49165",
          "CVE-2026-49166",
          "CVE-2026-49167",
          "CVE-2026-49168",
          "CVE-2026-49170",
          "CVE-2026-49171",
          "CVE-2026-49172",
          "CVE-2026-49174",
          "CVE-2026-49175",
          "CVE-2026-49176",
          "CVE-2026-49177",
          "CVE-2026-49178",
          "CVE-2026-49180",
          "CVE-2026-49183",
          "CVE-2026-49184",
          "CVE-2026-49783",
          "CVE-2026-49784",
          "CVE-2026-49787",
          "CVE-2026-49788",
          "CVE-2026-49789",
          "CVE-2026-49790",
          "CVE-2026-49791",
          "CVE-2026-49792",
          "CVE-2026-49793",
          "CVE-2026-49794",
          "CVE-2026-49795",
          "CVE-2026-49796",
          "CVE-2026-49797",
          "CVE-2026-49798",
          "CVE-2026-49799",
          "CVE-2026-49800",
          "CVE-2026-49801",
          "CVE-2026-49802",
          "CVE-2026-49803",
          "CVE-2026-49804",
          "CVE-2026-49805",
          "CVE-2026-49806",
          "CVE-2026-49807",
          "CVE-2026-49808",
          "CVE-2026-50293",
          "CVE-2026-50294",
          "CVE-2026-50295",
          "CVE-2026-50296",
          "CVE-2026-50297",
          "CVE-2026-50298",
          "CVE-2026-50299",
          "CVE-2026-50300",
          "CVE-2026-50302",
          "CVE-2026-50303",
          "CVE-2026-50305",
          "CVE-2026-50306",
          "CVE-2026-50307",
          "CVE-2026-50308",
          "CVE-2026-50309",
          "CVE-2026-50310",
          "CVE-2026-50311",
          "CVE-2026-50312",
          "CVE-2026-50313",
          "CVE-2026-50315",
          "CVE-2026-50316",
          "CVE-2026-50317",
          "CVE-2026-50318",
          "CVE-2026-50321",
          "CVE-2026-50322",
          "CVE-2026-50323",
          "CVE-2026-50325",
          "CVE-2026-50326",
          "CVE-2026-50327",
          "CVE-2026-50329",
          "CVE-2026-50330",
          "CVE-2026-50331",
          "CVE-2026-50332",
          "CVE-2026-50333",
          "CVE-2026-50334",
          "CVE-2026-50335",
          "CVE-2026-50336",
          "CVE-2026-50337",
          "CVE-2026-50339",
          "CVE-2026-50340",
          "CVE-2026-50341",
          "CVE-2026-50342",
          "CVE-2026-50343",
          "CVE-2026-50344",
          "CVE-2026-50345",
          "CVE-2026-50346",
          "CVE-2026-50347",
          "CVE-2026-50348",
          "CVE-2026-50350",
          "CVE-2026-50351",
          "CVE-2026-50352",
          "CVE-2026-50353",
          "CVE-2026-50354",
          "CVE-2026-50356",
          "CVE-2026-50357",
          "CVE-2026-50358",
          "CVE-2026-50359",
          "CVE-2026-50360",
          "CVE-2026-50361",
          "CVE-2026-50362",
          "CVE-2026-50363",
          "CVE-2026-50364",
          "CVE-2026-50365",
          "CVE-2026-50366",
          "CVE-2026-50367",
          "CVE-2026-50369",
          "CVE-2026-50371",
          "CVE-2026-50372",
          "CVE-2026-50373",
          "CVE-2026-50374",
          "CVE-2026-50375",
          "CVE-2026-50376",
          "CVE-2026-50377",
          "CVE-2026-50378",
          "CVE-2026-50379",
          "CVE-2026-50380",
          "CVE-2026-50381",
          "CVE-2026-50382",
          "CVE-2026-50383",
          "CVE-2026-50384",
          "CVE-2026-50385",
          "CVE-2026-50386",
          "CVE-2026-50387",
          "CVE-2026-50388",
          "CVE-2026-50389",
          "CVE-2026-50390",
          "CVE-2026-50391",
          "CVE-2026-50392",
          "CVE-2026-50393",
          "CVE-2026-50394",
          "CVE-2026-50396",
          "CVE-2026-50397",
          "CVE-2026-50398",
          "CVE-2026-50399",
          "CVE-2026-50400",
          "CVE-2026-50401",
          "CVE-2026-50402",
          "CVE-2026-50403",
          "CVE-2026-50404",
          "CVE-2026-50405",
          "CVE-2026-50406",
          "CVE-2026-50407",
          "CVE-2026-50409",
          "CVE-2026-50410",
          "CVE-2026-50411",
          "CVE-2026-50412",
          "CVE-2026-50413",
          "CVE-2026-50414",
          "CVE-2026-50415",
          "CVE-2026-50416",
          "CVE-2026-50417",
          "CVE-2026-50418",
          "CVE-2026-50419",
          "CVE-2026-50420",
          "CVE-2026-50421",
          "CVE-2026-50422",
          "CVE-2026-50423",
          "CVE-2026-50424",
          "CVE-2026-50425",
          "CVE-2026-50427",
          "CVE-2026-50429",
          "CVE-2026-50430",
          "CVE-2026-50431",
          "CVE-2026-50432",
          "CVE-2026-50433",
          "CVE-2026-50434",
          "CVE-2026-50435",
          "CVE-2026-50436",
          "CVE-2026-50437",
          "CVE-2026-50439",
          "CVE-2026-50440",
          "CVE-2026-50441",
          "CVE-2026-50442",
          "CVE-2026-50445",
          "CVE-2026-50447",
          "CVE-2026-50448",
          "CVE-2026-50449",
          "CVE-2026-50450",
          "CVE-2026-50451",
          "CVE-2026-50452",
          "CVE-2026-50453",
          "CVE-2026-50454",
          "CVE-2026-50455",
          "CVE-2026-50456",
          "CVE-2026-50457",
          "CVE-2026-50458",
          "CVE-2026-50459",
          "CVE-2026-50460",
          "CVE-2026-50461",
          "CVE-2026-50462",
          "CVE-2026-50463",
          "CVE-2026-50465",
          "CVE-2026-50466",
          "CVE-2026-50469",
          "CVE-2026-50470",
          "CVE-2026-50471",
          "CVE-2026-50473",
          "CVE-2026-50474",
          "CVE-2026-50475",
          "CVE-2026-50476",
          "CVE-2026-50477",
          "CVE-2026-50478",
          "CVE-2026-50482",
          "CVE-2026-50483",
          "CVE-2026-50484",
          "CVE-2026-50485",
          "CVE-2026-50486",
          "CVE-2026-50487",
          "CVE-2026-50488",
          "CVE-2026-50489",
          "CVE-2026-50490",
          "CVE-2026-50491",
          "CVE-2026-50492",
          "CVE-2026-50493",
          "CVE-2026-50494",
          "CVE-2026-50495",
          "CVE-2026-50496",
          "CVE-2026-50497",
          "CVE-2026-50498",
          "CVE-2026-50499",
          "CVE-2026-50500",
          "CVE-2026-50501",
          "CVE-2026-50502",
          "CVE-2026-50503",
          "CVE-2026-50504",
          "CVE-2026-50505",
          "CVE-2026-50509",
          "CVE-2026-50647",
          "CVE-2026-50655",
          "CVE-2026-50661",
          "CVE-2026-50666",
          "CVE-2026-50667",
          "CVE-2026-50668",
          "CVE-2026-50669",
          "CVE-2026-50670",
          "CVE-2026-50672",
          "CVE-2026-50673",
          "CVE-2026-50674",
          "CVE-2026-50676",
          "CVE-2026-50677",
          "CVE-2026-50679",
          "CVE-2026-50680",
          "CVE-2026-50681",
          "CVE-2026-50682",
          "CVE-2026-50686",
          "CVE-2026-50687",
          "CVE-2026-50688",
          "CVE-2026-50689",
          "CVE-2026-50690",
          "CVE-2026-50692",
          "CVE-2026-50694",
          "CVE-2026-50695",
          "CVE-2026-50696",
          "CVE-2026-50697",
          "CVE-2026-54107",
          "CVE-2026-54109",
          "CVE-2026-54111",
          "CVE-2026-54112",
          "CVE-2026-54114",
          "CVE-2026-54115",
          "CVE-2026-54119",
          "CVE-2026-54122",
          "CVE-2026-54124",
          "CVE-2026-54125",
          "CVE-2026-54126",
          "CVE-2026-54127",
          "CVE-2026-54128",
          "CVE-2026-54129",
          "CVE-2026-54132",
          "CVE-2026-54982",
          "CVE-2026-54983",
          "CVE-2026-54986",
          "CVE-2026-54987",
          "CVE-2026-54989",
          "CVE-2026-54990",
          "CVE-2026-54991",
          "CVE-2026-54992",
          "CVE-2026-54993",
          "CVE-2026-54995",
          "CVE-2026-54996",
          "CVE-2026-54997",
          "CVE-2026-54999",
          "CVE-2026-55000",
          "CVE-2026-55003",
          "CVE-2026-55004",
          "CVE-2026-55144",
          "CVE-2026-56168",
          "CVE-2026-56173",
          "CVE-2026-56175",
          "CVE-2026-56176",
          "CVE-2026-56181",
          "CVE-2026-56182",
          "CVE-2026-56183",
          "CVE-2026-56184",
          "CVE-2026-56186",
          "CVE-2026-56187",
          "CVE-2026-56188",
          "CVE-2026-56189",
          "CVE-2026-56190",
          "CVE-2026-56194",
          "CVE-2026-56643",
          "CVE-2026-56644",
          "CVE-2026-56647",
          "CVE-2026-56648",
          "CVE-2026-56649",
          "CVE-2026-56650",
          "CVE-2026-57083",
          "CVE-2026-57084",
          "CVE-2026-57085",
          "CVE-2026-57087",
          "CVE-2026-57089",
          "CVE-2026-57090",
          "CVE-2026-57091",
          "CVE-2026-57092",
          "CVE-2026-57093",
          "CVE-2026-57094",
          "CVE-2026-57095",
          "CVE-2026-57096",
          "CVE-2026-57097",
          "CVE-2026-57976",
          "CVE-2026-57979",
          "CVE-2026-57982",
          "CVE-2026-58526",
          "CVE-2026-58527",
          "CVE-2026-58528",
          "CVE-2026-58530",
          "CVE-2026-58531",
          "CVE-2026-58532",
          "CVE-2026-58533",
          "CVE-2026-58534",
          "CVE-2026-58535",
          "CVE-2026-58536",
          "CVE-2026-58537",
          "CVE-2026-58538",
          "CVE-2026-58539",
          "CVE-2026-58540",
          "CVE-2026-58541",
          "CVE-2026-58542",
          "CVE-2026-58543",
          "CVE-2026-58544",
          "CVE-2026-58545",
          "CVE-2026-58546",
          "CVE-2026-58547",
          "CVE-2026-58594",
          "CVE-2026-58601",
          "CVE-2026-58602",
          "CVE-2026-58608",
          "CVE-2026-58609",
          "CVE-2026-58610",
          "CVE-2026-58613",
          "CVE-2026-58614",
          "CVE-2026-58619",
          "CVE-2026-58626",
          "CVE-2026-58628",
          "CVE-2026-58629",
          "CVE-2026-58632",
          "CVE-2026-58635",
          "CVE-2026-58637",
          "CVE-2026-58638",
          "CVE-2026-58640"
        ],
        "details": [
          {
            "id": "CVE-2026-33842",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39646,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-34328",
            "title": "Windows Audio Service Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39644,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-34346",
            "title": "Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability",
            "summary": "Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0027,
            "epssPercentile": 0.18916,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-34348",
            "title": "Windows Event Logging Service Information Disclosure Vulnerability",
            "summary": "Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00907,
            "epssPercentile": 0.57588,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-34349",
            "title": "Windows Media Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39645,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-40378",
            "title": "Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability",
            "summary": "Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65473,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-40400",
            "title": "Windows PowerShell Remote Code Execution Vulnerability",
            "summary": "Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00868,
            "epssPercentile": 0.56393,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-40422",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33743,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-41087",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39643,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-42900",
            "title": "Microsoft Windows App Store Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00542,
            "epssPercentile": 0.43631,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-42975",
            "title": "Windows Bluetooth Port Driver Remote Code Execution",
            "summary": "Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00536,
            "epssPercentile": 0.43257,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-42982",
            "title": "Windows Secure Kernel Mode Elevation of Privilege Vulnerability",
            "summary": "Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26114,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-42990",
            "title": "SQL Server ODBC driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59786,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-44800",
            "title": "Windows Push Notifications Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.1017,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-44806",
            "title": "Windows Secure Channel Denial of Service Vulnerability",
            "summary": "Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65471,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48571",
            "title": "Windows App Package Installer Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18081,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48572",
            "title": "Windows App Package Installer Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10166,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49162",
            "title": "Microsoft Brokering File System Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18081,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49164",
            "title": "Windows Active Directory Domain Services Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53952,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49165",
            "title": "Microsoft Windows App Store Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00338,
            "epssPercentile": 0.26611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49166",
            "title": "Windows Print Configuration Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26113,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49167",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 4.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0035,
            "epssPercentile": 0.28037,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49168",
            "title": "Storage Spaces Direct Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36763,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49170",
            "title": "Windows StateRepository API Server file Elevation of Privilege Vulnerability",
            "summary": "Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.2211,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49171",
            "title": "Windows Speech Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.003,
            "epssPercentile": 0.22345,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49172",
            "title": "Windows FTP Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59785,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49174",
            "title": "DNS Client Tampering Vulnerability",
            "summary": "Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0027,
            "epssPercentile": 0.18886,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49175",
            "title": "Windows DNS Client Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26114,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49176",
            "title": "Windows WalletService Elevation of Privilege Vulnerability",
            "summary": "Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00471,
            "epssPercentile": 0.39116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49177",
            "title": "Windows TCP/IP Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00443,
            "epssPercentile": 0.37172,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49178",
            "title": "Windows Active Directory Domain Services Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.57789,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49180",
            "title": "Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00444,
            "epssPercentile": 0.37219,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49183",
            "title": "Windows Clipboard Server Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10168,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49184",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00337,
            "epssPercentile": 0.26479,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49783",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26114,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49784",
            "title": "Microsoft Windows App Store Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10169,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49787",
            "title": "HTTP.sys Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65471,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49788",
            "title": "HTTP/2 Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in HTTP/2 allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.6547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49789",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29002,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49790",
            "title": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
            "summary": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29001,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49791",
            "title": "Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0038,
            "epssPercentile": 0.31138,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49792",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26115,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49793",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26113,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49794",
            "title": "Windows USB Audio Class Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00468,
            "epssPercentile": 0.3893,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49795",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26115,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49796",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49797",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38802,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49798",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.",
            "score": 9.3,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00364,
            "epssPercentile": 0.29518,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49799",
            "title": "Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability",
            "summary": "Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01138,
            "epssPercentile": 0.64468,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49800",
            "title": "Windows Web Proxy Auto-Discovery Protocol (WPAD) Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26115,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49801",
            "title": "Windows SMB Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33744,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49802",
            "title": "Windows USB Print Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10169,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49803",
            "title": "Windows AppX Deployment Extensions Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.1017,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49804",
            "title": "Windows USB Video Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows USB Video Driver allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00483,
            "epssPercentile": 0.39895,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49805",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00236,
            "epssPercentile": 0.14488,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49806",
            "title": "Windows USB Print Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10171,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49807",
            "title": "Windows DirectX Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows DirectX allows an unauthorized attacker to disclose information locally.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00506,
            "epssPercentile": 0.41392,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49808",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10167,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50293",
            "title": "Windows Internal Task Bar Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Internal Task Bar allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50294",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized attacker to disclose information locally.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00506,
            "epssPercentile": 0.41392,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50295",
            "title": "Windows Zero Trust DNS Security Feature Bypass Vulnerability",
            "summary": "Improper privilege management in Microsoft Windows DNS allows an authorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00302,
            "epssPercentile": 0.22534,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50296",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Graphics Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18079,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50297",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00236,
            "epssPercentile": 0.14488,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50298",
            "title": "Windows Spaceport.sys Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Spaceport.sys allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36765,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50299",
            "title": "Windows Storage Spaces Direct Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to execute code with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36764,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50300",
            "title": "Windows DWM Core Library Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows Kernel allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50302",
            "title": "Windows Cryptographic Services Security Feature Bypass Vulnerability",
            "summary": "Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 4.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00334,
            "epssPercentile": 0.2625,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50303",
            "title": "Windows Key Guard Security Feature Bypass Vulnerability",
            "summary": "Use of a cryptographic primitive with a risky implementation in Windows Key Guard allows an authorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0027,
            "epssPercentile": 0.18916,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50305",
            "title": "Microsoft Brokering File System Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17026,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50306",
            "title": "Windows TCP/IP Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26104,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50307",
            "title": "Windows TCP/IP Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows TCP/IP allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20052,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50308",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38802,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50309",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26104,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50310",
            "title": "Windows Human Interface Device Information Disclosure Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information locally.",
            "score": 4.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23556,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50311",
            "title": "Windows Server Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50312",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 4.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0035,
            "epssPercentile": 0.28037,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50313",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38794,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50315",
            "title": "Windows Image Acquisition Elevation of Privilege Vulnerability",
            "summary": "Null pointer dereference in Windows Image Acquisition allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26103,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50316",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39648,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50317",
            "title": "Windows Operating Systems Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Operating Systems allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11648,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50318",
            "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26103,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50321",
            "title": "Windows USB Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11649,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50322",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10167,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50323",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18079,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50325",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00236,
            "epssPercentile": 0.14488,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50326",
            "title": "Windows Unified Consent System Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Unified Consent System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50327",
            "title": "Windows Media Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Media allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50329",
            "title": "Microsoft DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50330",
            "title": "Windows Remote Desktop Client Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01252,
            "epssPercentile": 0.6748,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50331",
            "title": "Windows Application Model Core API Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Application Model allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50332",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50333",
            "title": "Windows Spaceport.sys Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50334",
            "title": "Windows Push Notification Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Notification allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39645,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50335",
            "title": "Windows Operating Systems Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50336",
            "title": "Windows Media Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Media allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26103,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50337",
            "title": "Windows Notification Elevation of Privilege Vulnerability",
            "summary": "Incorrect type conversion or cast in Windows Notification allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26104,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50339",
            "title": "Windows Push Notification Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39645,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50340",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Runtime allows an authorized attacker to elevate privileges over a network.",
            "score": 8.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00742,
            "epssPercentile": 0.52348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50341",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33741,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50342",
            "title": "Windows MIDI Service Module Elevation of Privileges Vulnerability",
            "summary": "Improper access control in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50343",
            "title": "Microsoft Install Service Elevation of Privilege Vulnerability",
            "summary": "Improper privilege management in Microsoft Install Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50344",
            "title": "Windows OLE Elevation of Privilege Vulnerability",
            "summary": "Improper authorization in Windows OLE allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50345",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10168,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50346",
            "title": "Netlogon RPC Elevation of Privilege Vulnerability",
            "summary": "Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50347",
            "title": "Windows Data.dll Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38792,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50348",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0036,
            "epssPercentile": 0.29103,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50350",
            "title": "Windows Trusted Runtime Interface Driver Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Trusted Runtime Interface Driver allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39646,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50351",
            "title": "Windows Audio Compression Manager (ACM) Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Audio Compression Manager (ACM) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50352",
            "title": "Windows Cryptographic Services Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50353",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50354",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26129,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50356",
            "title": "Microsoft Windows App Store Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10168,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50357",
            "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50358",
            "title": "Windows Media Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Media allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20051,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50359",
            "title": "Microsoft XML Core Services Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft XML Core Services allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20051,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50360",
            "title": "Windows SMB Server Elevation of Privilege Vulnerability",
            "summary": "Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00778,
            "epssPercentile": 0.53532,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50361",
            "title": "Microsoft Brokering File System Elevation of Privilege Vulnerability",
            "summary": "Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17027,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50362",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38801,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50363",
            "title": "Windows Push Notifications Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26102,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50364",
            "title": "Windows Backup Service Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows Server Backup allows an authorized attacker to elevate privileges locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00469,
            "epssPercentile": 0.38948,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50365",
            "title": "Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability",
            "summary": "Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00542,
            "epssPercentile": 0.43604,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50366",
            "title": "Windows Active Directory Domain Services Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01138,
            "epssPercentile": 0.64468,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50367",
            "title": "Windows Sensor Data Service Elevation of Privilege Vulnerability",
            "summary": "Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26103,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50369",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00701,
            "epssPercentile": 0.50891,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50371",
            "title": "Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows LUAFV allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10167,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50372",
            "title": "Windows Redirected Drive Buffering System Elevation of Privilege Vulnerability",
            "summary": "Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18081,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50373",
            "title": "Windows Search Service Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50374",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00347,
            "epssPercentile": 0.27656,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50375",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DirectX allows an authorized attacker to elevate privileges locally.",
            "score": 6.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00295,
            "epssPercentile": 0.21728,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50376",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50377",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00409,
            "epssPercentile": 0.34158,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50378",
            "title": "Windows Key Guard Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Key Guard allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11649,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50379",
            "title": "Windows Media Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00509,
            "epssPercentile": 0.41581,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50380",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.",
            "score": 9.6,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.54859,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50381",
            "title": "Composite Image File System driver (cimfs.sys) Information Disclosure Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Composite Image File System Driver allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33744,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50382",
            "title": "DirectX Graphics Kernel Remote Code Execution Vulnerability",
            "summary": "Untrusted pointer dereference in Windows DirectX allows an authorized attacker to execute code locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50383",
            "title": "Windows Print Spooler Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33741,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50384",
            "title": "Windows Clip Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clip Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10168,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50385",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17027,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50386",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38791,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50387",
            "title": "Windows GDI Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26111,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50388",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38797,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50389",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39644,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50390",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20053,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50391",
            "title": "Windows Group Policy Elevation of Privilege Vulnerability",
            "summary": "Improper privilege management in Windows Group Policy allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.2211,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50392",
            "title": "Windows Secure Kernel Mode Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18082,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50393",
            "title": "Windows Kernel-Mode Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20052,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50394",
            "title": "Windows Media Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39643,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50396",
            "title": "Windows Kernel-Mode Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20051,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50397",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18081,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50398",
            "title": "Windows Media Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00569,
            "epssPercentile": 0.4503,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50399",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26111,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50400",
            "title": "Windows App Package Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows App Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.2611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50401",
            "title": "Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Cloud Files Mini Filter Driver allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33744,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50402",
            "title": "NTFS Elevation of Privilege Vulnerability",
            "summary": "Incorrect conversion between numeric types in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.2611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50403",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10165,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50404",
            "title": "Windows Media Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10166,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50405",
            "title": "Windows Filtering Platform Elevation of Privilege Vulnerability",
            "summary": "Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50406",
            "title": "Windows Backup Engine Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Backup Engine allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20052,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50407",
            "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50409",
            "title": "Windows Overlay Filter Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Overlay Filter allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50410",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18079,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50411",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50412",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50413",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26098,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50414",
            "title": "Windows Media Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00569,
            "epssPercentile": 0.45031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50415",
            "title": "Windows Media Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Media allows an unauthorized attacker to disclose information over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0086,
            "epssPercentile": 0.56162,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50416",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 3.3,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00458,
            "epssPercentile": 0.38212,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50417",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26111,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50418",
            "title": "Windows System Secure Feature Bypass Vulnerability",
            "summary": "Improper access control in Windows System allows an unauthorized attacker to bypass a security feature locally.",
            "score": 5.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00266,
            "epssPercentile": 0.18272,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50419",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.",
            "score": 3.3,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00458,
            "epssPercentile": 0.38211,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50420",
            "title": "HTTP.sys Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to disclose information locally.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00408,
            "epssPercentile": 0.34085,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50421",
            "title": "Windows Connected User Experiences and Telemetry Elevation of Privilege Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.2611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50422",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50423",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50424",
            "title": "Windows Domain Controller Denial of Service Vulnerability",
            "summary": "Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65473,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50425",
            "title": "Windows Internal System User Profile Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Internal System User Profile allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50427",
            "title": "Content Delivery Manager Elevation of Privilege Vulnerability",
            "summary": "Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17026,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50429",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network.",
            "score": 8.2,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01069,
            "epssPercentile": 0.62606,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50430",
            "title": "Windows Push Notification Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39648,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50431",
            "title": "Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability",
            "summary": "Windows Quality of Service (QoS) Packet Scheduler Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39648,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50432",
            "title": "Window Virtual Filtering Platform (VFP) Denial of Service Vulnerability",
            "summary": "Use after free in Windows Virtual Filtering Platform (VFP) allows an authorized attacker to deny service over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00953,
            "epssPercentile": 0.59049,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50433",
            "title": "Windows Media Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Media allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50434",
            "title": "Windows Push Notification Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50435",
            "title": "Windows Overlay Filter Elevation of Privilege Vulnerability",
            "summary": "Buffer over-read in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50436",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50437",
            "title": "Windows DWM Core Library Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50439",
            "title": "Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53953,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50440",
            "title": "Windows Audio Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Audio Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11649,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50441",
            "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
            "summary": "Untrusted pointer dereference in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.2611,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50442",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39646,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50445",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58032,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50447",
            "title": "Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59787,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50448",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38799,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50449",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18082,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50450",
            "title": "Windows Network Connections Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10166,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50451",
            "title": "Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00307,
            "epssPercentile": 0.23134,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50452",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0036,
            "epssPercentile": 0.29103,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50453",
            "title": "Windows USB Audio Class Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0051,
            "epssPercentile": 0.41673,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50454",
            "title": "Windows User Interface Core Elevation of Privilege Vulnerability",
            "summary": "Relative path traversal in Windows User Interface Core allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0037,
            "epssPercentile": 0.30148,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50455",
            "title": "Universal Plug and Play (upnp.dll) Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33743,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50456",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39646,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50457",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17027,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50458",
            "title": "Microsoft Brokering File System Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17025,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50459",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22679,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50460",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00542,
            "epssPercentile": 0.4363,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50461",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38801,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50462",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00457,
            "epssPercentile": 0.38194,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50463",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01027,
            "epssPercentile": 0.61357,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50465",
            "title": "Windows DNS Client Tampering Vulnerability",
            "summary": "Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50466",
            "title": "Microsoft Brokering File System Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Brokering File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26096,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50469",
            "title": "Windows Projected File System Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows Projected File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0037,
            "epssPercentile": 0.30149,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50470",
            "title": "Windows Network Policy Server SNMP Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01027,
            "epssPercentile": 0.61358,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50471",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38793,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50473",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39644,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50474",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.54859,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50475",
            "title": "Windows Kernel Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Kernel allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.00375,
            "epssPercentile": 0.30678,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Medium technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50476",
            "title": "Windows Network Connections Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Windows allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20051,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50477",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.261,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50478",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26097,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50482",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29001,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50483",
            "title": "Windows Graphics Component Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39643,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50484",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26112,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50485",
            "title": "Windows Hyper-V Denial of Service Vulnerability",
            "summary": "Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.",
            "score": 4.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00656,
            "epssPercentile": 0.49112,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50486",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26097,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50487",
            "title": "Windows DNS Client Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Windows DNS allows an unauthorized attacker to elevate privileges over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53953,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50488",
            "title": "Clipboard User Service Elevation of Privilege Vulnerability",
            "summary": "Improper neutralization of special elements used in a command ('command injection') in Windows Clipboard User Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00322,
            "epssPercentile": 0.24873,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50489",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50490",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20054,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50491",
            "title": "Code Integrity DLL (ci.dll) Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20054,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50492",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36764,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50493",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26098,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50494",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26098,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50495",
            "title": "DNS Client Tampering Vulnerability",
            "summary": "Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00302,
            "epssPercentile": 0.22534,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50496",
            "title": "Windows Network Policy Server SNMP Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50497",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58032,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50498",
            "title": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
            "summary": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00363,
            "epssPercentile": 0.29377,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50499",
            "title": "Windows Print Spooler Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50500",
            "title": "Windows Netlogon Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00742,
            "epssPercentile": 0.52348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50501",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00363,
            "epssPercentile": 0.29377,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50502",
            "title": "Windows Event Logging Service Remote Code Execution Vulnerability",
            "summary": "Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00654,
            "epssPercentile": 0.49042,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50503",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10169,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50504",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.5803,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50505",
            "title": "Windows Message Queuing Service (MSMQ) Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00742,
            "epssPercentile": 0.52348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50509",
            "title": "Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability",
            "summary": "Deserialization of untrusted data in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0353,
            "epssPercentile": 0.88474,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50647",
            "title": "Active Directory Federation Server Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50655",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38797,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50661",
            "title": "Windows BitLocker Security Feature Bypass Vulnerability",
            "summary": "Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00481,
            "epssPercentile": 0.39822,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50666",
            "title": "Windows Remote Access Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.5779,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50667",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11651,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50668",
            "title": "Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36764,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50669",
            "title": "Windows Telephony Server Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.1017,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50670",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26096,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50672",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10166,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50673",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Null pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.1165,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50674",
            "title": "Windows USB Print Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.2005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50676",
            "title": "Windows Media Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.1165,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50677",
            "title": "Windows Media Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Media allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17026,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50679",
            "title": "Windows Search Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26096,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50680",
            "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally.",
            "score": 8.2,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00338,
            "epssPercentile": 0.26665,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50681",
            "title": "Windows Secure Channel Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39645,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50682",
            "title": "Active Directory Denial of Service Vulnerability",
            "summary": "Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58293,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50686",
            "title": "Windows OLE Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00707,
            "epssPercentile": 0.5113,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50687",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26095,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50688",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20053,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50689",
            "title": "Windows Clipboard Server Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17026,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50690",
            "title": "Windows SMB Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50692",
            "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.261,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50694",
            "title": "Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53953,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50695",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65468,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50696",
            "title": "Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Internet Key Exchange (IKE) Protocol allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50697",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00395,
            "epssPercentile": 0.32743,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54107",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11651,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54109",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54111",
            "title": "Universal Print Management Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10165,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54112",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10171,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54114",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54115",
            "title": "Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26115,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54119",
            "title": "Windows Active Directory Denial of Service Vulnerability",
            "summary": "Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54122",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00364,
            "epssPercentile": 0.29518,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54124",
            "title": "Windows Terminal Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.388,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54125",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17027,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54126",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58034,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54127",
            "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Hyper-V allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00305,
            "epssPercentile": 0.22804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54128",
            "title": "Windows DHCP Client Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00364,
            "epssPercentile": 0.29519,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54129",
            "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20054,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54132",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36764,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54982",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00535,
            "epssPercentile": 0.43236,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54983",
            "title": "Windows Active Directory Federation Services Denial of Service Vulnerability",
            "summary": "Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01174,
            "epssPercentile": 0.65471,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54986",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26113,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54987",
            "title": "Windows Overlay Filter Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Overlay Filter allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54989",
            "title": "Quality Windows Audio/Video Experience (QWAVE) Elevation of Privilege Vulnerability",
            "summary": "Use after free in Quality Windows Audio/Video Experience (QWAVE) service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20052,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54990",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.54861,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54991",
            "title": "Windows USB Print Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11649,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54992",
            "title": "Microsoft Message Queuing Queue Manager Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00337,
            "epssPercentile": 0.26479,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54993",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38795,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54995",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53953,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54996",
            "title": "Windows USB Print Driver Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10171,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54997",
            "title": "Windows SMB Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54999",
            "title": "Windows TCP/IP Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0041,
            "epssPercentile": 0.34281,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55000",
            "title": "Windows USB Print Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00339,
            "epssPercentile": 0.26781,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55003",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55004",
            "title": "Windows Print Configuration Elevation of Privilege Vulnerability",
            "summary": "Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26116,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-55144",
            "title": "Windows Cryptography API: Next Generation (CNG) Tampering Vulnerability",
            "summary": "Missing cryptographic step in Windows CryptoAPI allows an authorized attacker to perform tampering locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00225,
            "epssPercentile": 0.13158,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56168",
            "title": "Windows SMB Server Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01138,
            "epssPercentile": 0.64469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56173",
            "title": "Windows WebView Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18078,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56175",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26112,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56176",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26112,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56181",
            "title": "Windows Network Address Translation (NAT) Spoofing Vulnerability",
            "summary": "Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.",
            "score": 8.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00276,
            "epssPercentile": 0.19734,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56182",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26112,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56183",
            "title": "Windows MIDI Service Module Elevation of Privileges Vulnerability",
            "summary": "Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18079,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56184",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39643,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56186",
            "title": "Windows Secure Channel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01106,
            "epssPercentile": 0.63644,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56187",
            "title": "Windows MIDI Service Module Elevation of Privileges Vulnerability",
            "summary": "Use after free in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20054,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56188",
            "title": "Windows Server Network driver Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00607,
            "epssPercentile": 0.46852,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56189",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00393,
            "epssPercentile": 0.32499,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56190",
            "title": "Remote Desktop Protocol Remote Code Execution Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00974,
            "epssPercentile": 0.59787,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56194",
            "title": "Windows NFS Server Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.5779,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56643",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26107,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56644",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56647",
            "title": "Windows Remote Access Service Infrastructure Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.57789,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56648",
            "title": "Windows NFS Server Elevation of Privilege Vulnerability",
            "summary": "Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00509,
            "epssPercentile": 0.41581,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56649",
            "title": "Windows Network File System Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File System allows an unauthorized attacker to execute code over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00699,
            "epssPercentile": 0.50808,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56650",
            "title": "Windows Network File System Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57083",
            "title": "Windows Media Photo Codec Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.4355,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57084",
            "title": "Windows File Explorer Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00541,
            "epssPercentile": 0.43549,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57085",
            "title": "Windows Print Spooler Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Print Spooler Components allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0037,
            "epssPercentile": 0.30143,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57087",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00792,
            "epssPercentile": 0.53969,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57089",
            "title": "Windows SMB Server Network Transport Driver (srvnet.sys) Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00665,
            "epssPercentile": 0.49498,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57090",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.54858,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57091",
            "title": "Windows File History Service Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows File History Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57092",
            "title": "Microsoft Windows VMSwitch Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.",
            "score": 9.9,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.57791,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57093",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00279,
            "epssPercentile": 0.20053,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57094",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.54859,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57095",
            "title": "Win32k Elevation of Privilege Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an unauthorized attacker to elevate privileges locally.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00489,
            "epssPercentile": 0.40353,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57096",
            "title": "Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26106,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57097",
            "title": "Microsoft XML Security Feature Bypass Vulnerability",
            "summary": "Untrusted search path in Microsoft XML allows an unauthorized attacker to bypass a security feature with a physical attack.",
            "score": 6.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00503,
            "epssPercentile": 0.41172,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57976",
            "title": "Windows Active Directory Domain Services Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01138,
            "epssPercentile": 0.64468,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57979",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58034,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57982",
            "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00995,
            "epssPercentile": 0.60375,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58526",
            "title": "Windows Storage Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Storage allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11648,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58527",
            "title": "Windows Runtime Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.1165,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58528",
            "title": "Windows USB Audio Class Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00524,
            "epssPercentile": 0.42584,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58530",
            "title": "Windows Resilient File System (ReFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00363,
            "epssPercentile": 0.29377,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58531",
            "title": "Windows SMB Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00509,
            "epssPercentile": 0.41581,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58532",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.261,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58533",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58033,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58534",
            "title": "Windows Input Method Editor (IME) Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26095,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58535",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58536",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26095,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58537",
            "title": "Microsoft NAT Helper Components (ipnathlp.dll) Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft NAT Helper Components (ipnathlp.dll) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.261,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58538",
            "title": "Windows Bluetooth Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26101,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58539",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58033,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58540",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58541",
            "title": "Microsoft DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26102,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58542",
            "title": "Windows Media Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00363,
            "epssPercentile": 0.29376,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58543",
            "title": "Universal Print Management Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00244,
            "epssPercentile": 0.15497,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58544",
            "title": "Windows Management Services Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.1808,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58545",
            "title": "Windows Kernel Security Feature Bypass Vulnerability",
            "summary": "Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0035,
            "epssPercentile": 0.27951,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58546",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58033,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58547",
            "title": "Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00407,
            "epssPercentile": 0.33974,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58594",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00819,
            "epssPercentile": 0.5486,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58601",
            "title": "Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability",
            "summary": "Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26102,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58602",
            "title": "Windows Kernel-Mode Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel Mode Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26102,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58608",
            "title": "Windows Print Spooler Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00569,
            "epssPercentile": 0.45031,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58609",
            "title": "Windows Graphics Component Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38794,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58610",
            "title": "Microsoft Windows Media Foundation Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.38797,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58613",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.00377,
            "epssPercentile": 0.30833,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58614",
            "title": "Windows Kernel Security Feature Bypass Vulnerability",
            "summary": "Out-of-bounds read in Windows Kernel allows an authorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33743,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58619",
            "title": "Windows Sensor Data Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.1808,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58626",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00913,
            "epssPercentile": 0.57789,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58628",
            "title": "Windows Wireless Network Manager Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10171,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58629",
            "title": "DirectX Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.1808,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58632",
            "title": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26101,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58635",
            "title": "Windows Narrator Braille Elevation of Privilege Vulnerability",
            "summary": "Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00322,
            "epssPercentile": 0.24873,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58637",
            "title": "Windows Client-Side Caching Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18082,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58638",
            "title": "Windows Boot Loader Security Feature Bypass Vulnerability",
            "summary": "Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.",
            "score": 6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00235,
            "epssPercentile": 0.14327,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58640",
            "title": "Windows NTFS Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29001,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [
        {
          "title": "Limited Intel IPF compatibility issue",
          "status": "resolved",
          "summary": "Microsoft states that the update was temporarily unavailable for a limited number of affected Dell devices and that KB5121767 resolved the issue."
        }
      ],
      "deployment_effects": [
        "Review the vendor's KB5121767 guidance if the July release was withheld from an affected Dell device.",
        "Dynamic-update deployment guidance requires matching boot.stl content in installation media.",
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "This record covers one Windows 11 cumulative release, not the full Microsoft July product or CVE set.",
        "The complete Security Update Guide relationship set was not imported.",
        "Restart requirements are not asserted in this bounded record.",
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial July security update publication."
        },
        {
          "revision": 2,
          "observed_at": "2026-07-15",
          "summary": "Microsoft amended the Intel IPF availability announcement."
        },
        {
          "revision": 3,
          "observed_at": "2026-08-05",
          "summary": "Microsoft added a picture-password change note while retaining the same canonical KB record."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.9,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-57092",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-windows-msrc-2026-07-windows-kb37864969-microsoft-configuration-manager-2509",
      "slug": "microsoft-2026-07-windows-msrc-2026-07-windows-kb37864969-microsoft-configuration-manager-2509",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-07-windows-kb37864969",
      "title": "Deploy Microsoft Windows update for Microsoft Configuration Manager 2509",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://learn.microsoft.com/en-us/intune/configmgr/hotfix/2509/36949461",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft Configuration Manager 2509",
      "platform": "Windows",
      "release_version": "5.0.9141.1030",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Configuration Manager 2509.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-47301"
        ],
        "details": [
          {
            "id": "CVE-2026-47301",
            "title": "Configuration Manager Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00964,
            "epssPercentile": 0.5939,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-47301",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-windows-msrc-2026-07-windows-kb38232642-microsoft-configuration-manager-2603",
      "slug": "microsoft-2026-07-windows-msrc-2026-07-windows-kb38232642-microsoft-configuration-manager-2603",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-07-windows-kb38232642",
      "title": "Deploy Microsoft Windows update for Microsoft Configuration Manager 2603",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://learn.microsoft.com/en-us/intune/configmgr/hotfix/2603/38232642",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Microsoft Configuration Manager 2603",
      "platform": "Windows",
      "release_version": "5.0.9146.1021",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Configuration Manager 2603.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-47301"
        ],
        "details": [
          {
            "id": "CVE-2026-47301",
            "title": "Configuration Manager Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00964,
            "epssPercentile": 0.5939,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-47301",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-windows-msrc-2026-07-windows-release-notes-windows-remote-help",
      "slug": "microsoft-2026-07-windows-msrc-2026-07-windows-release-notes-windows-remote-help",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-07-windows-release-notes",
      "title": "Deploy Microsoft Windows update for Windows Remote Help",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://catalog.update.microsoft.com/ScopedViewInline.aspx?updateid=206fb4e4-b796-4a47-af4f-87e57fd7d35a",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Windows Remote Help",
      "platform": "Windows",
      "release_version": "5.2.1037.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows Remote Help.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-55014"
        ],
        "details": [
          {
            "id": "CVE-2026-55014",
            "title": "Windows Remote Help Defense Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Remote Help Defense allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22109,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-55014",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-07-windows-msrc-2026-07-windows-release-notes-windows-admin-center",
      "slug": "microsoft-2026-07-windows-msrc-2026-07-windows-release-notes-windows-admin-center",
      "cycle_id": "2026-07",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-07-windows-release-notes",
      "title": "Deploy Microsoft Windows update for Windows Admin Center",
      "source_title": "2026-07 Microsoft Security Update Guide",
      "source_url": "https://aka.ms/downloadWAC",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Windows Admin Center",
      "platform": "Windows",
      "release_version": "2.6.5.16, 2.7.4",
      "action_type": "deploy-patch",
      "restart_required": "no",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 6 linked CVEs for Windows Admin Center.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 6,
        "ids": [
          "CVE-2026-56169",
          "CVE-2026-56185",
          "CVE-2026-56196",
          "CVE-2026-56197",
          "CVE-2026-57107",
          "CVE-2026-58631"
        ],
        "details": [
          {
            "id": "CVE-2026-56169",
            "title": "Windows Admin Center Elevation of Privilege Vulnerability",
            "summary": "Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00506,
            "epssPercentile": 0.41381,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56185",
            "title": "Windows Admin Center Information Disclosure Vulnerability",
            "summary": "Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0084,
            "epssPercentile": 0.55507,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56196",
            "title": "Windows Admin Center (WAC) Remote Code Execution Vulnerability",
            "summary": "Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00955,
            "epssPercentile": 0.59115,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56197",
            "title": "Windows Admin Center (WAC) Remote Code Execution Vulnerability",
            "summary": "Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00922,
            "epssPercentile": 0.58017,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-57107",
            "title": "Windows Admin Center Elevation of Privilege Vulnerability",
            "summary": "Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58631",
            "title": "Windows Admin Center (WAC) Remote Code Execution Vulnerability",
            "summary": "Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-56197",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "The reviewed source does not require a restart.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "adobe-apsb26-79",
      "slug": "adobe-apsb26-79",
      "cycle_id": "2026-07",
      "vendor_id": "adobe",
      "vendor_name": "Adobe",
      "source_id": "adobe-security-bulletins",
      "advisory_id": "APSB26-79",
      "title": "Update Adobe Illustrator to the fixed Adobe release",
      "source_title": "APSB26-79 : Security update available for Adobe Illustrator",
      "source_url": "https://helpx.adobe.com/security/products/illustrator/apsb26-79.html",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Adobe Illustrator",
      "platform": "Windows and macOS",
      "release_version": "29.8.9, 30.6",
      "action_type": "upgrade-release",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 9.3; Adobe priority 3",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "Adobe published APSB26-79 on Patch Tuesday for Adobe Illustrator. The bulletin links 5 CVEs and provides fixed release guidance.",
      "cves": {
        "state": "complete-for-advisory",
        "vendor_stated_count": 5,
        "ids": [
          "CVE-2026-48275",
          "CVE-2026-48334",
          "CVE-2026-48335",
          "CVE-2026-48336",
          "CVE-2026-48337"
        ],
        "details": [
          {
            "id": "CVE-2026-48275",
            "title": "Illustrator | Untrusted Search Path (CWE-426)",
            "summary": "Illustrator is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.",
            "score": 8.6,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00293,
            "epssPercentile": 0.21573,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "30.6; 29.8.9",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48334",
            "title": "Illustrator | Improper Input Validation (CWE-20)",
            "summary": "Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.",
            "score": 9.3,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.004,
            "epssPercentile": 0.3329,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "30.6; 29.8.9",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48335",
            "title": "Illustrator | Out-of-bounds Write (CWE-787)",
            "summary": "Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17163,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "30.6; 29.8.9",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48336",
            "title": "Illustrator | Out-of-bounds Write (CWE-787)",
            "summary": "Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17163,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "30.6; 29.8.9",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48337",
            "title": "Illustrator | Out-of-bounds Write (CWE-787)",
            "summary": "Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17163,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "30.6; 29.8.9",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update path and test the fixed release against managed plug-ins, workflows and file formats before broad deployment."
      ],
      "data_gaps": [
        "Restart requirements are not asserted unless the reviewed bulletin states them explicitly."
      ],
      "provenance": [
        {
          "field": "advisory_identity_and_release",
          "source_path": "adobe-bulletin/solution",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships",
          "source_path": "adobe-bulletin/vulnerability-details",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial APSB26-79 publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The bulletin identity, release date, fixed versions, platforms, vendor signals and complete public CVE list were generated from the official Adobe bulletin and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-48334",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "adobe-apsb26-78",
      "slug": "adobe-apsb26-78",
      "cycle_id": "2026-07",
      "vendor_id": "adobe",
      "vendor_name": "Adobe",
      "source_id": "adobe-security-bulletins",
      "advisory_id": "APSB26-78",
      "title": "Update Adobe After Effects to the fixed Adobe release",
      "source_title": "APSB26-78 : Security update available for Adobe After Effects",
      "source_url": "https://helpx.adobe.com/security/products/after_effects/apsb26-78.html",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Adobe After Effects",
      "platform": "Windows and macOS",
      "release_version": "25.6.6, 26.3",
      "action_type": "upgrade-release",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 7.8; Adobe priority 3",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "Adobe published APSB26-78 on Patch Tuesday for Adobe After Effects. The bulletin links 3 CVEs and provides fixed release guidance.",
      "cves": {
        "state": "complete-for-advisory",
        "vendor_stated_count": 3,
        "ids": [
          "CVE-2026-34690",
          "CVE-2026-48274",
          "CVE-2026-48367"
        ],
        "details": [
          {
            "id": "CVE-2026-34690",
            "title": "After Effects | Stack-based Buffer Overflow (CWE-121)",
            "summary": "After Effects is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00513,
            "epssPercentile": 0.41839,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "26.3; 25.6.6",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48274",
            "title": "After Effects | Out-of-bounds Write (CWE-787)",
            "summary": "After Effects is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17161,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "26.3; 25.6.6",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48367",
            "title": "After Effects | Out-of-bounds Write (CWE-787)",
            "summary": "After Effects is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17164,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "26.3; 25.6.6",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update path and test the fixed release against managed plug-ins, workflows and file formats before broad deployment."
      ],
      "data_gaps": [
        "Restart requirements are not asserted unless the reviewed bulletin states them explicitly."
      ],
      "provenance": [
        {
          "field": "advisory_identity_and_release",
          "source_path": "adobe-bulletin/solution",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships",
          "source_path": "adobe-bulletin/vulnerability-details",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial APSB26-78 publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The bulletin identity, release date, fixed versions, platforms, vendor signals and complete public CVE list were generated from the official Adobe bulletin and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-48367",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "adobe-apsb26-83",
      "slug": "adobe-apsb26-83",
      "cycle_id": "2026-07",
      "vendor_id": "adobe",
      "vendor_name": "Adobe",
      "source_id": "adobe-security-bulletins",
      "advisory_id": "APSB26-83",
      "title": "Update Adobe Animate to the fixed Adobe release",
      "source_title": "APSB26-83 : Security update available for Adobe Animate",
      "source_url": "https://helpx.adobe.com/security/products/animate/apsb26-83.html",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Adobe Animate",
      "platform": "Windows and macOS",
      "release_version": "23.0.16, 24.0.14",
      "action_type": "upgrade-release",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 8.6; Adobe priority 3",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "Adobe published APSB26-83 on Patch Tuesday for Adobe Animate. The bulletin links 6 CVEs and provides fixed release guidance.",
      "cves": {
        "state": "complete-for-advisory",
        "vendor_stated_count": 6,
        "ids": [
          "CVE-2026-48345",
          "CVE-2026-48346",
          "CVE-2026-48347",
          "CVE-2026-48348",
          "CVE-2026-48349",
          "CVE-2026-48350"
        ],
        "details": [
          {
            "id": "CVE-2026-48345",
            "title": "Animate | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)",
            "summary": "Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.",
            "score": 8.2,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00891,
            "epssPercentile": 0.57075,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "23.0.16; 24.0.14",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48346",
            "title": "Animate | Untrusted Search Path (CWE-426)",
            "summary": "Animate is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.",
            "score": 7.9,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00262,
            "epssPercentile": 0.17861,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "23.0.16; 24.0.14",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48347",
            "title": "Animate | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)",
            "summary": "Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.",
            "score": 7.7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00721,
            "epssPercentile": 0.51602,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "23.0.16; 24.0.14",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48348",
            "title": "Animate | Incorrect Authorization (CWE-863)",
            "summary": "Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.",
            "score": 7.7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00218,
            "epssPercentile": 0.12207,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "23.0.16; 24.0.14",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48349",
            "title": "Animate | Incorrect Authorization (CWE-863)",
            "summary": "Animate is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00235,
            "epssPercentile": 0.14401,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "23.0.16; 24.0.14",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48350",
            "title": "Animate | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)",
            "summary": "Animate is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to access sensitive files or directories outside the intended restrictions. Exploitation of this issue requires user interaction in that a victim must open a malicious file. ",
            "score": 8.6,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00328,
            "epssPercentile": 0.25455,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "23.0.16; 24.0.14",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update path and test the fixed release against managed plug-ins, workflows and file formats before broad deployment."
      ],
      "data_gaps": [
        "Restart requirements are not asserted unless the reviewed bulletin states them explicitly."
      ],
      "provenance": [
        {
          "field": "advisory_identity_and_release",
          "source_path": "adobe-bulletin/solution",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships",
          "source_path": "adobe-bulletin/vulnerability-details",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial APSB26-83 publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The bulletin identity, release date, fixed versions, platforms, vendor signals and complete public CVE list were generated from the official Adobe bulletin and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.6,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-48350",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "adobe-apsb26-71",
      "slug": "adobe-apsb26-71",
      "cycle_id": "2026-07",
      "vendor_id": "adobe",
      "vendor_name": "Adobe",
      "source_id": "adobe-security-bulletins",
      "advisory_id": "APSB26-71",
      "title": "Update Adobe Audition to the fixed Adobe release",
      "source_title": "APSB26-71 : Security update available for Adobe Audition",
      "source_url": "https://helpx.adobe.com/security/products/audition/apsb26-71.html",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Adobe Audition",
      "platform": "Windows and macOS",
      "release_version": "26.3, 25.6.6",
      "action_type": "upgrade-release",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 7.8; Adobe priority 3",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "Adobe published APSB26-71 on Patch Tuesday for Adobe Audition. The bulletin links 6 CVEs and provides fixed release guidance.",
      "cves": {
        "state": "complete-for-advisory",
        "vendor_stated_count": 6,
        "ids": [
          "CVE-2026-47967",
          "CVE-2026-47968",
          "CVE-2026-47969",
          "CVE-2026-48309",
          "CVE-2026-48365",
          "CVE-2026-48368"
        ],
        "details": [
          {
            "id": "CVE-2026-47967",
            "title": "Audition | Out-of-bounds Write (CWE-787)",
            "summary": "Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17162,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "26.3; 25.6.6",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47968",
            "title": "Audition | Out-of-bounds Write (CWE-787)",
            "summary": "Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17162,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "26.3; 25.6.6",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47969",
            "title": "Audition | Out-of-bounds Read (CWE-125)",
            "summary": "Audition is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00261,
            "epssPercentile": 0.1766,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "26.3; 25.6.6",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48309",
            "title": "Audition | Out-of-bounds Write (CWE-787)",
            "summary": "Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17161,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "26.3; 25.6.6",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48365",
            "title": "Audition | Out-of-bounds Write (CWE-787)",
            "summary": "Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17165,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "26.3; 25.6.6",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48368",
            "title": "Audition | Out-of-bounds Write (CWE-787)",
            "summary": "Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17161,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "26.3; 25.6.6",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update path and test the fixed release against managed plug-ins, workflows and file formats before broad deployment."
      ],
      "data_gaps": [
        "Restart requirements are not asserted unless the reviewed bulletin states them explicitly."
      ],
      "provenance": [
        {
          "field": "advisory_identity_and_release",
          "source_path": "adobe-bulletin/solution",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships",
          "source_path": "adobe-bulletin/vulnerability-details",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial APSB26-71 publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The bulletin identity, release date, fixed versions, platforms, vendor signals and complete public CVE list were generated from the official Adobe bulletin and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-48368",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "adobe-apsb26-81",
      "slug": "adobe-apsb26-81",
      "cycle_id": "2026-07",
      "vendor_id": "adobe",
      "vendor_name": "Adobe",
      "source_id": "adobe-security-bulletins",
      "advisory_id": "APSB26-81",
      "title": "Update Adobe Bridge to the fixed Adobe release",
      "source_title": "APSB26-81 : Security update available for Adobe Bridge",
      "source_url": "https://helpx.adobe.com/security/products/bridge/apsb26-81.html",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Adobe Bridge",
      "platform": "Windows and macOS",
      "release_version": "15.1.6 (LTS), 16.0.4",
      "action_type": "upgrade-release",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 7.8",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "Adobe published APSB26-81 on Patch Tuesday for Adobe Bridge. The bulletin links 6 CVEs and provides fixed release guidance.",
      "cves": {
        "state": "complete-for-advisory",
        "vendor_stated_count": 6,
        "ids": [
          "CVE-2026-48311",
          "CVE-2026-48339",
          "CVE-2026-48340",
          "CVE-2026-48341",
          "CVE-2026-48342",
          "CVE-2026-48343"
        ],
        "details": [
          {
            "id": "CVE-2026-48311",
            "title": "Bridge | Out-of-bounds Write (CWE-787)",
            "summary": "Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.1716,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "16.0.4; 15.1.6",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48339",
            "title": "Bridge | Heap-based Buffer Overflow (CWE-122)",
            "summary": "Bridge is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00337,
            "epssPercentile": 0.26584,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "16.0.4; 15.1.6",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48340",
            "title": "Bridge | Untrusted Pointer Dereference (CWE-822)",
            "summary": "Bridge is affected by an Untrusted Pointer Dereference vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00293,
            "epssPercentile": 0.21572,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "16.0.4; 15.1.6",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48341",
            "title": "Bridge | Out-of-bounds Write (CWE-787)",
            "summary": "Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17163,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "16.0.4; 15.1.6",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48342",
            "title": "Bridge | Integer Overflow or Wraparound (CWE-190)",
            "summary": "Bridge is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00314,
            "epssPercentile": 0.23934,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "16.0.4; 15.1.6",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48343",
            "title": "Bridge | Out-of-bounds Write (CWE-787)",
            "summary": "Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17161,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "16.0.4; 15.1.6",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update path and test the fixed release against managed plug-ins, workflows and file formats before broad deployment."
      ],
      "data_gaps": [
        "Restart requirements are not asserted unless the reviewed bulletin states them explicitly."
      ],
      "provenance": [
        {
          "field": "advisory_identity_and_release",
          "source_path": "adobe-bulletin/solution",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships",
          "source_path": "adobe-bulletin/vulnerability-details",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial APSB26-81 publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The bulletin identity, release date, fixed versions, platforms, vendor signals and complete public CVE list were generated from the official Adobe bulletin and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-48343",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "adobe-apsb26-82",
      "slug": "adobe-apsb26-82",
      "cycle_id": "2026-07",
      "vendor_id": "adobe",
      "vendor_name": "Adobe",
      "source_id": "adobe-security-bulletins",
      "advisory_id": "APSB26-82",
      "title": "Update Adobe ColdFusion to the fixed Adobe release",
      "source_title": "APSB26-82 : Security update available for Adobe ColdFusion",
      "source_url": "https://helpx.adobe.com/security/products/coldfusion/apsb26-82.html",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Adobe ColdFusion",
      "platform": "All",
      "release_version": "Update 11, Update 22",
      "action_type": "upgrade-release",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 9.9; Adobe priority 1",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "Adobe published APSB26-82 on Patch Tuesday for Adobe ColdFusion. The bulletin links 13 CVEs and provides fixed release guidance.",
      "cves": {
        "state": "complete-for-advisory",
        "vendor_stated_count": 13,
        "ids": [
          "CVE-2026-48284",
          "CVE-2026-48318",
          "CVE-2026-48319",
          "CVE-2026-48320",
          "CVE-2026-48321",
          "CVE-2026-48322",
          "CVE-2026-48324",
          "CVE-2026-48325",
          "CVE-2026-48327",
          "CVE-2026-48328",
          "CVE-2026-48329",
          "CVE-2026-48332",
          "CVE-2026-48338"
        ],
        "details": [
          {
            "id": "CVE-2026-48284",
            "title": "ColdFusion | Improper Input Validation (CWE-20)",
            "summary": "ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.",
            "score": 9.6,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.04895,
            "epssPercentile": 0.91502,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "11; 22",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48318",
            "title": "ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)",
            "summary": "ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.",
            "score": 9.9,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01097,
            "epssPercentile": 0.6343,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "11; 22",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48319",
            "title": "ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)",
            "summary": "ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.",
            "score": 9.1,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.3229,
            "epssPercentile": 0.98208,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "11; 22",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48320",
            "title": "ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79)",
            "summary": "ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue requires user interaction in that a victim must open ",
            "score": 8.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0529,
            "epssPercentile": 0.92039,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "11; 22",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48321",
            "title": "ColdFusion | Incorrect Authorization (CWE-863)",
            "summary": "ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.",
            "score": 9.3,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00471,
            "epssPercentile": 0.39077,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "11; 22",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48322",
            "title": "ColdFusion | Improper Control of Generation of Code ('Code Injection') (CWE-94)",
            "summary": "ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.",
            "score": 9.9,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01172,
            "epssPercentile": 0.65393,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "11; 22",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48324",
            "title": "ColdFusion | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)",
            "summary": "ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.",
            "score": 9.1,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01439,
            "epssPercentile": 0.71411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "11; 22",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48325",
            "title": "ColdFusion | Missing Authentication for Critical Function (CWE-306)",
            "summary": "ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.",
            "score": 9.3,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00553,
            "epssPercentile": 0.44224,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "11; 22",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48327",
            "title": "ColdFusion | Incorrect Authorization (CWE-863)",
            "summary": "ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.",
            "score": 9,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00408,
            "epssPercentile": 0.34104,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "11; 22",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48328",
            "title": "ColdFusion | Improper Input Validation (CWE-20)",
            "summary": "ColdFusion is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.",
            "score": 7.7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0082,
            "epssPercentile": 0.54901,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "11; 22",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48329",
            "title": "ColdFusion | Insufficient Session Expiration (CWE-613)",
            "summary": "ColdFusion is affected by an Insufficient Session Expiration vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.",
            "score": 2.7,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00567,
            "epssPercentile": 0.44954,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "11; 22",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48332",
            "title": "ColdFusion | Server-Side Request Forgery (SSRF) (CWE-918)",
            "summary": "ColdFusion is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.",
            "score": 7.7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0079,
            "epssPercentile": 0.53913,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "11; 22",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48338",
            "title": "ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)",
            "summary": "ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00468,
            "epssPercentile": 0.3887,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "11; 22",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update path and test the fixed release against managed plug-ins, workflows and file formats before broad deployment."
      ],
      "data_gaps": [
        "Restart requirements are not asserted unless the reviewed bulletin states them explicitly."
      ],
      "provenance": [
        {
          "field": "advisory_identity_and_release",
          "source_path": "adobe-bulletin/solution",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships",
          "source_path": "adobe-bulletin/vulnerability-details",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial APSB26-82 publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The bulletin identity, release date, fixed versions, platforms, vendor signals and complete public CVE list were generated from the official Adobe bulletin and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.9,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-48322",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "adobe-apsb26-80",
      "slug": "adobe-apsb26-80",
      "cycle_id": "2026-07",
      "vendor_id": "adobe",
      "vendor_name": "Adobe",
      "source_id": "adobe-security-bulletins",
      "advisory_id": "APSB26-80",
      "title": "Update Content Credentials SDK to the fixed Adobe release",
      "source_title": "APSB26-80 : Security update available for Content Credentials SDK",
      "source_url": "https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-80.html",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Content Credentials SDK",
      "platform": "Windows, macOS, Linux, iOS, Android",
      "release_version": "c2pa-v0.85.2, c2patool-v0.26.65, @contentauth/c2pa-web@0.9.0",
      "action_type": "upgrade-release",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 8.2; Adobe priority 3",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "Adobe published APSB26-80 on Patch Tuesday for Content Credentials SDK. The bulletin links 12 CVEs and provides fixed release guidance.",
      "cves": {
        "state": "complete-for-advisory",
        "vendor_stated_count": 12,
        "ids": [
          "CVE-2026-48287",
          "CVE-2026-48290",
          "CVE-2026-48295",
          "CVE-2026-48296",
          "CVE-2026-48298",
          "CVE-2026-48302",
          "CVE-2026-48312",
          "CVE-2026-48351",
          "CVE-2026-48352",
          "CVE-2026-48353",
          "CVE-2026-48354",
          "CVE-2026-48357"
        ],
        "details": [
          {
            "id": "CVE-2026-48287",
            "title": "CAI Content Credentials | Untrusted Search Path (CWE-426)",
            "summary": "CAI Content Credentials is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.",
            "score": 7.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00225,
            "epssPercentile": 0.13023,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "c2pa-v0.85.2; c2patool-v0.26.65; @contentauth/c2pa-web@0.9.0",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48290",
            "title": "CAI Content Credentials | Server-Side Request Forgery (SSRF) (CWE-918)",
            "summary": "CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim mus",
            "score": 8.2,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00295,
            "epssPercentile": 0.21762,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "c2pa-v0.85.2; c2patool-v0.26.65; @contentauth/c2pa-web@0.9.0",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48295",
            "title": "CAI Content Credentials | Insufficiently Protected Credentials (CWE-522)",
            "summary": "CAI Content Credentials is affected by an Insufficiently Protected Credentials vulnerability that could result in disclosure of sensitive information. An attacker could leverage this vulnerability to gain unauthorized read access. Exploitation of this issue does not require user interaction.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55328,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "c2pa-v0.85.2; c2patool-v0.26.65; @contentauth/c2pa-web@0.9.0",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48296",
            "title": "CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191)",
            "summary": "CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00259,
            "epssPercentile": 0.17496,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "c2pa-v0.85.2; c2patool-v0.26.65; @contentauth/c2pa-web@0.9.0",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48298",
            "title": "CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191)",
            "summary": "CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00259,
            "epssPercentile": 0.17496,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "c2pa-v0.85.2; c2patool-v0.26.65; @contentauth/c2pa-web@0.9.0",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48302",
            "title": "CAI Content Credentials | Improper Input Validation (CWE-20)",
            "summary": "CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00267,
            "epssPercentile": 0.18573,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "c2pa-v0.85.2; c2patool-v0.26.65; @contentauth/c2pa-web@0.9.0",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48312",
            "title": "CAI Content Credentials | Improper Input Validation (CWE-20)",
            "summary": "CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00282,
            "epssPercentile": 0.20438,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "c2pa-v0.85.2; c2patool-v0.26.65; @contentauth/c2pa-web@0.9.0",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48351",
            "title": "CAI Content Credentials | Improper Input Validation (CWE-20)",
            "summary": "CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00927,
            "epssPercentile": 0.58191,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "c2pa-v0.85.2; c2patool-v0.26.65; @contentauth/c2pa-web@0.9.0",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48352",
            "title": "CAI Content Credentials | Improper Input Validation (CWE-20)",
            "summary": "CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00927,
            "epssPercentile": 0.58191,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "c2pa-v0.85.2; c2patool-v0.26.65; @contentauth/c2pa-web@0.9.0",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48353",
            "title": "CAI Content Credentials | Improper Input Validation (CWE-20)",
            "summary": "CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00263,
            "epssPercentile": 0.18009,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "c2pa-v0.85.2; c2patool-v0.26.65; @contentauth/c2pa-web@0.9.0",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48354",
            "title": "CAI Content Credentials | Integer Overflow or Wraparound (CWE-190)",
            "summary": "CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00289,
            "epssPercentile": 0.21121,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "c2pa-v0.85.2; c2patool-v0.26.65; @contentauth/c2pa-web@0.9.0",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48357",
            "title": "CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)",
            "summary": "CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00259,
            "epssPercentile": 0.17496,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "c2pa-v0.85.2; c2patool-v0.26.65; @contentauth/c2pa-web@0.9.0",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update path and test the fixed release against managed plug-ins, workflows and file formats before broad deployment."
      ],
      "data_gaps": [
        "Restart requirements are not asserted unless the reviewed bulletin states them explicitly."
      ],
      "provenance": [
        {
          "field": "advisory_identity_and_release",
          "source_path": "adobe-bulletin/solution",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships",
          "source_path": "adobe-bulletin/vulnerability-details",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial APSB26-80 publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The bulletin identity, release date, fixed versions, platforms, vendor signals and complete public CVE list were generated from the official Adobe bulletin and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.2,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-48290",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "adobe-apsb26-77",
      "slug": "adobe-apsb26-77",
      "cycle_id": "2026-07",
      "vendor_id": "adobe",
      "vendor_name": "Adobe",
      "source_id": "adobe-security-bulletins",
      "advisory_id": "APSB26-77",
      "title": "Update Adobe Creative Cloud Desktop Application to the fixed Adobe release",
      "source_title": "APSB26-77 : Security update available for Adobe Creative Cloud Desktop Application",
      "source_url": "https://helpx.adobe.com/security/products/creative-cloud/apsb26-77.html",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Adobe Creative Cloud Desktop Application",
      "platform": "Windows",
      "release_version": "6.10.0.252.3",
      "action_type": "upgrade-release",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 7.8; Adobe priority 3",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "Adobe published APSB26-77 on Patch Tuesday for Adobe Creative Cloud Desktop Application. The bulletin links 2 CVEs and provides fixed release guidance.",
      "cves": {
        "state": "complete-for-advisory",
        "vendor_stated_count": 2,
        "ids": [
          "CVE-2026-48272",
          "CVE-2026-48344"
        ],
        "details": [
          {
            "id": "CVE-2026-48272",
            "title": "Creative Cloud Desktop | Uncontrolled Search Path Element (CWE-427)",
            "summary": "Creative Cloud Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00227,
            "epssPercentile": 0.13381,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "6.10.0.252.3",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48344",
            "title": "GoCart | Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367)",
            "summary": "Creative Cloud Desktop is affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00171,
            "epssPercentile": 0.06713,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "6.10.0.252.3",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update path and test the fixed release against managed plug-ins, workflows and file formats before broad deployment."
      ],
      "data_gaps": [
        "Restart requirements are not asserted unless the reviewed bulletin states them explicitly."
      ],
      "provenance": [
        {
          "field": "advisory_identity_and_release",
          "source_path": "adobe-bulletin/solution",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships",
          "source_path": "adobe-bulletin/vulnerability-details",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial APSB26-77 publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The bulletin identity, release date, fixed versions, platforms, vendor signals and complete public CVE list were generated from the official Adobe bulletin and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-48344",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "adobe-apsb26-74",
      "slug": "adobe-apsb26-74",
      "cycle_id": "2026-07",
      "vendor_id": "adobe",
      "vendor_name": "Adobe",
      "source_id": "adobe-security-bulletins",
      "advisory_id": "APSB26-74",
      "title": "Update Adobe Experience Manager to the fixed Adobe release",
      "source_title": "APSB26-74 : Security update available for Adobe Experience Manager",
      "source_url": "https://helpx.adobe.com/security/products/experience-manager/apsb26-74.html",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Adobe Experience Manager",
      "platform": "All",
      "release_version": "AEM Cloud Service (CS) Release 2026.6.0, 6.5 LTS Service Pack 2 - Hotfix for NPR-43972, 6.5 Service Pack 25 - Hotfix for NPR-43971",
      "action_type": "upgrade-release",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 9.6; Adobe priority 3",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "Adobe published APSB26-74 on Patch Tuesday for Adobe Experience Manager. The bulletin links 14 CVEs and provides fixed release guidance.",
      "cves": {
        "state": "complete-for-advisory",
        "vendor_stated_count": 14,
        "ids": [
          "CVE-2023-25690",
          "CVE-2026-48252",
          "CVE-2026-48253",
          "CVE-2026-48254",
          "CVE-2026-48255",
          "CVE-2026-48257",
          "CVE-2026-48259",
          "CVE-2026-48260",
          "CVE-2026-48261",
          "CVE-2026-48262",
          "CVE-2026-48263",
          "CVE-2026-48310",
          "CVE-2026-48355",
          "CVE-2026-48359"
        ],
        "details": [
          {
            "id": "CVE-2023-25690",
            "title": "Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy",
            "summary": "Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack. Configurations are affected when mod_proxy is enabled along with some form of RewriteRule or ProxyPassMatch in which a non-specific pattern matches some portion of the user-supplied request-target (URL) data and is then re-inserted into the proxied request-target using variable substitution. For ex",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "NIST NVD",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "CISA Vulnrichment records proof-of-concept exploitation in its SSVC data. BlackTree has not independently executed or validated exploit material.",
            "epss": 0.84508,
            "epssPercentile": 0.99686,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path and a public exploit reference; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48252",
            "title": "Adobe Experience Manager | Missing Authentication for Critical Function (CWE-306)",
            "summary": "Adobe Experience Manager is affected by a Missing Authentication for Critical Function vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction. Scope is changed.",
            "score": 8.6,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00892,
            "epssPercentile": 0.57124,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "2026.6.0; SP2 - Hotfix for NPR-43972; 6.5.25 - Hotfix for NPR-43971",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48253",
            "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
            "summary": "Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.",
            "score": 5.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29027,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "2026.6.0; SP2 - Hotfix for NPR-43972; 6.5.25 - Hotfix for NPR-43971",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48254",
            "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
            "summary": "Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.",
            "score": 5.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29026,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "2026.6.0; SP2 - Hotfix for NPR-43972; 6.5.25 - Hotfix for NPR-43971",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48255",
            "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
            "summary": "Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.",
            "score": 5.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29027,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "2026.6.0; SP2 - Hotfix for NPR-43972; 6.5.25 - Hotfix for NPR-43971",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48257",
            "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
            "summary": "Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.",
            "score": 5.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29028,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "2026.6.0; SP2 - Hotfix for NPR-43972; 6.5.25 - Hotfix for NPR-43971",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48259",
            "title": "Adobe Experience Manager | Server-Side Request Forgery (SSRF) (CWE-918)",
            "summary": "Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could leverage this vulnerability to issue unauthorized server-side requests, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue does not require user interacti",
            "score": 9.6,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00897,
            "epssPercentile": 0.57283,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "2026.6.0; SP2 - Hotfix for NPR-43972; 6.5.25 - Hotfix for NPR-43971",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48260",
            "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
            "summary": "Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.",
            "score": 5.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29027,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "2026.6.0; SP2 - Hotfix for NPR-43972; 6.5.25 - Hotfix for NPR-43971",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48261",
            "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
            "summary": "Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.",
            "score": 5.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29027,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "2026.6.0; SP2 - Hotfix for NPR-43972; 6.5.25 - Hotfix for NPR-43971",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48262",
            "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
            "summary": "Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.",
            "score": 5.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29026,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "2026.6.0; SP2 - Hotfix for NPR-43972; 6.5.25 - Hotfix for NPR-43971",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48263",
            "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
            "summary": "Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.",
            "score": 5.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0039,
            "epssPercentile": 0.3222,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "2026.6.0; SP2 - Hotfix for NPR-43972; 6.5.25 - Hotfix for NPR-43971",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48310",
            "title": "Adobe Experience Manager | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)",
            "summary": "Adobe Experience Manager is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.",
            "score": 8.6,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01047,
            "epssPercentile": 0.61961,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "2026.6.0; SP2 - Hotfix for NPR-43972; 6.5.25 - Hotfix for NPR-43971",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48355",
            "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
            "summary": "Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.",
            "score": 5.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0039,
            "epssPercentile": 0.3222,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "2026.6.0; SP2 - Hotfix for NPR-43972; 6.5.25 - Hotfix for NPR-43971",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48359",
            "title": "Adobe Experience Manager | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)",
            "summary": "Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to read sensitive files, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue does not require user i",
            "score": 9.6,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01004,
            "epssPercentile": 0.60679,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "2026.6.0; SP2 - Hotfix for NPR-43972; 6.5.25 - Hotfix for NPR-43971",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update path and test the fixed release against managed plug-ins, workflows and file formats before broad deployment."
      ],
      "data_gaps": [
        "Restart requirements are not asserted unless the reviewed bulletin states them explicitly."
      ],
      "provenance": [
        {
          "field": "advisory_identity_and_release",
          "source_path": "adobe-bulletin/solution",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships",
          "source_path": "adobe-bulletin/vulnerability-details",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial APSB26-74 publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The bulletin identity, release date, fixed versions, platforms, vendor signals and complete public CVE list were generated from the official Adobe bulletin and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2023-25690",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "adobe-apsb26-72",
      "slug": "adobe-apsb26-72",
      "cycle_id": "2026-07",
      "vendor_id": "adobe",
      "vendor_name": "Adobe",
      "source_id": "adobe-security-bulletins",
      "advisory_id": "APSB26-72",
      "title": "Update Adobe Media Encoder to the fixed Adobe release",
      "source_title": "APSB26-72 : Security update available for Adobe Media Encoder",
      "source_url": "https://helpx.adobe.com/security/products/media-encoder/apsb26-72.html",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Adobe Media Encoder",
      "platform": "Windows and macOS",
      "release_version": "26.3, 25.6.6",
      "action_type": "upgrade-release",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 7.8; Adobe priority 3",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "Adobe published APSB26-72 on Patch Tuesday for Adobe Media Encoder. The bulletin links 5 CVEs and provides fixed release guidance.",
      "cves": {
        "state": "complete-for-advisory",
        "vendor_stated_count": 5,
        "ids": [
          "CVE-2026-47971",
          "CVE-2026-47976",
          "CVE-2026-47979",
          "CVE-2026-48366",
          "CVE-2026-48370"
        ],
        "details": [
          {
            "id": "CVE-2026-47971",
            "title": "Media Encoder | Stack-based Buffer Overflow (CWE-121)",
            "summary": "Media Encoder is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00337,
            "epssPercentile": 0.26584,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "26.3; 25.6.6",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47976",
            "title": "Media Encoder | Out-of-bounds Write (CWE-787)",
            "summary": "Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17164,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "26.3; 25.6.6",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47979",
            "title": "Media Encoder | Out-of-bounds Read (CWE-125)",
            "summary": "Media Encoder is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00261,
            "epssPercentile": 0.1766,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "26.3; 25.6.6",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48366",
            "title": "Media Encoder | Out-of-bounds Write (CWE-787)",
            "summary": "Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17164,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "26.3; 25.6.6",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48370",
            "title": "Media Encoder | Out-of-bounds Write (CWE-787)",
            "summary": "Media Encoder is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17164,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "26.3; 25.6.6",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update path and test the fixed release against managed plug-ins, workflows and file formats before broad deployment."
      ],
      "data_gaps": [
        "Restart requirements are not asserted unless the reviewed bulletin states them explicitly."
      ],
      "provenance": [
        {
          "field": "advisory_identity_and_release",
          "source_path": "adobe-bulletin/solution",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships",
          "source_path": "adobe-bulletin/vulnerability-details",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial APSB26-72 publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The bulletin identity, release date, fixed versions, platforms, vendor signals and complete public CVE list were generated from the official Adobe bulletin and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-48370",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "adobe-apsb26-73",
      "slug": "adobe-apsb26-73",
      "cycle_id": "2026-07",
      "vendor_id": "adobe",
      "vendor_name": "Adobe",
      "source_id": "adobe-security-bulletins",
      "advisory_id": "APSB26-73",
      "title": "Update Adobe Commerce to the fixed Adobe release",
      "source_title": "APSB26-73 : Security update available for Adobe Commerce",
      "source_url": "https://helpx.adobe.com/security/products/magento/apsb26-73.html",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Adobe Commerce",
      "platform": "All",
      "release_version": "2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul, 2.4.5-2026-jul, 2.4.4-2026-jul, 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul, 1.3.3-2026-jul, 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul, 1.21.0",
      "action_type": "upgrade-release",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 9.6; Adobe priority 2",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "Adobe published APSB26-73 on Patch Tuesday for Adobe Commerce. The bulletin links 14 CVEs and provides fixed release guidance.",
      "cves": {
        "state": "complete-for-advisory",
        "vendor_stated_count": 14,
        "ids": [
          "CVE-2026-47984",
          "CVE-2026-47988",
          "CVE-2026-47992",
          "CVE-2026-47994",
          "CVE-2026-47995",
          "CVE-2026-47996",
          "CVE-2026-47997",
          "CVE-2026-47998",
          "CVE-2026-47999",
          "CVE-2026-48000",
          "CVE-2026-48001",
          "CVE-2026-48356",
          "CVE-2026-48358",
          "CVE-2026-48371"
        ],
        "details": [
          {
            "id": "CVE-2026-47984",
            "title": "Adobe Commerce | Incorrect Authorization (CWE-863)",
            "summary": "Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and limited write access. Exploitation of this issue does not require user interaction.",
            "score": 8.2,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00641,
            "epssPercentile": 0.48414,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul, 2.4.5-2026-jul, 2.4.4-2026-jul; 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul, 1.3.3-2026-jul; 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul; 1.21.0",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47988",
            "title": "Adobe Commerce | Incorrect Authorization (CWE-863)",
            "summary": "Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and limited write access, causing a limited disruption to availability. Exploitation of this issue does not require user interaction.",
            "score": 8.6,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00685,
            "epssPercentile": 0.50306,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul, 2.4.5-2026-jul, 2.4.4-2026-jul; 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul, 1.3.3-2026-jul; 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul; 1.21.0",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47992",
            "title": "Adobe Commerce | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)",
            "summary": "Adobe Commerce is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could exploit this vulnerability to execute malicious SQL commands, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue",
            "score": 7.2,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00991,
            "epssPercentile": 0.60262,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul, 2.4.5-2026-jul, 2.4.4-2026-jul; 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul, 1.3.3-2026-jul; 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul; 1.21.0",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47994",
            "title": "Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)",
            "summary": "Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.",
            "score": 8.7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00622,
            "epssPercentile": 0.47608,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul, 2.4.5-2026-jul, 2.4.4-2026-jul; 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul, 1.3.3-2026-jul; 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul; 1.21.0",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47995",
            "title": "Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)",
            "summary": "Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00397,
            "epssPercentile": 0.32953,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul, 2.4.5-2026-jul, 2.4.4-2026-jul; 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul, 1.3.3-2026-jul; 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul; 1.21.0",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47996",
            "title": "Adobe Commerce | Incorrect Authorization (CWE-863)",
            "summary": "Adobe Commerce is affected by an Incorrect Authorization vulnerability that could lead to arbitrary file system read. A high-privileged attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00875,
            "epssPercentile": 0.56632,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul, 2.4.5-2026-jul, 2.4.4-2026-jul; 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul, 1.3.3-2026-jul; 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul; 1.21.0",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47997",
            "title": "Adobe Commerce | Incorrect Authorization (CWE-863)",
            "summary": "Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00709,
            "epssPercentile": 0.51177,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul, 2.4.5-2026-jul, 2.4.4-2026-jul; 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul, 1.3.3-2026-jul; 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul; 1.21.0",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47998",
            "title": "Adobe Commerce | Incorrect Authorization (CWE-863)",
            "summary": "Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00709,
            "epssPercentile": 0.51178,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul, 2.4.5-2026-jul, 2.4.4-2026-jul; 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul, 1.3.3-2026-jul; 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul; 1.21.0",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-47999",
            "title": "Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)",
            "summary": "Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.",
            "score": 4.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00409,
            "epssPercentile": 0.34117,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul, 2.4.5-2026-jul, 2.4.4-2026-jul; 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul, 1.3.3-2026-jul; 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul; 1.21.0",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48000",
            "title": "Adobe Commerce | URL Redirection to Untrusted Site ('Open Redirect') (CWE-601)",
            "summary": "Adobe Commerce is affected by an Improper Redirect (Open Redirect) vulnerability that could result in a Security feature bypass. An attacker could construct a malicious URL that redirects a victim to an attacker-controlled site. Exploitation of this issue requires user interaction in that a victim must click on a malicious link. Scope is changed.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00456,
            "epssPercentile": 0.38137,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul, 2.4.5-2026-jul, 2.4.4-2026-jul; 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul, 1.3.3-2026-jul; 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul; 1.21.0",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48001",
            "title": "Adobe Commerce | Information Exposure (CWE-200)",
            "summary": "Adobe Commerce is affected by an Information Exposure vulnerability that could lead to a limited disclosure of sensitive information. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction.",
            "score": 3.7,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00506,
            "epssPercentile": 0.41367,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul, 2.4.5-2026-jul, 2.4.4-2026-jul; 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul, 1.3.3-2026-jul; 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul; 1.21.0",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48356",
            "title": "Adobe Commerce | Unrestricted Upload of File with Dangerous Type (CWE-434)",
            "summary": "Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is c",
            "score": 9.3,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01001,
            "epssPercentile": 0.60558,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul, 2.4.5-2026-jul, 2.4.4-2026-jul; 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul, 1.3.3-2026-jul; 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul; 1.21.0",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48358",
            "title": "Adobe Commerce | Improper Encoding or Escaping of Output (CWE-116)",
            "summary": "Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.",
            "score": 9.1,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01486,
            "epssPercentile": 0.72318,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul, 2.4.5-2026-jul, 2.4.4-2026-jul; 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul, 1.3.3-2026-jul; 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul; 1.21.0",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48371",
            "title": "Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)",
            "summary": "Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.",
            "score": 5.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0039,
            "epssPercentile": 0.3222,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul, 2.4.5-2026-jul, 2.4.4-2026-jul; 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul, 1.3.3-2026-jul; 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul; 1.21.0",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update path and test the fixed release against managed plug-ins, workflows and file formats before broad deployment."
      ],
      "data_gaps": [
        "Restart requirements are not asserted unless the reviewed bulletin states them explicitly."
      ],
      "provenance": [
        {
          "field": "advisory_identity_and_release",
          "source_path": "adobe-bulletin/solution",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships",
          "source_path": "adobe-bulletin/vulnerability-details",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial APSB26-73 publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The bulletin identity, release date, fixed versions, platforms, vendor signals and complete public CVE list were generated from the official Adobe bulletin and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-48356",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "adobe-apsb26-76",
      "slug": "adobe-apsb26-76",
      "cycle_id": "2026-07",
      "vendor_id": "adobe",
      "vendor_name": "Adobe",
      "source_id": "adobe-security-bulletins",
      "advisory_id": "APSB26-76",
      "title": "Update Adobe Premiere Pro to the fixed Adobe release",
      "source_title": "APSB26-76 : Security update available for Adobe Premiere Pro",
      "source_url": "https://helpx.adobe.com/security/products/premiere_pro/apsb26-76.html",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "Adobe Premiere Pro",
      "platform": "Windows and macOS",
      "release_version": "26.3, 25.6.6",
      "action_type": "upgrade-release",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 7.8; Adobe priority 3",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "Adobe published APSB26-76 on Patch Tuesday for Adobe Premiere Pro. The bulletin links 5 CVEs and provides fixed release guidance.",
      "cves": {
        "state": "complete-for-advisory",
        "vendor_stated_count": 5,
        "ids": [
          "CVE-2026-34641",
          "CVE-2026-48269",
          "CVE-2026-48270",
          "CVE-2026-48308",
          "CVE-2026-48369"
        ],
        "details": [
          {
            "id": "CVE-2026-34641",
            "title": "Premiere Pro | Out-of-bounds Write (CWE-787)",
            "summary": "Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00139,
            "epssPercentile": 0.03564,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "26.3; 25.6.6",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48269",
            "title": "Premiere Pro | Heap-based Buffer Overflow (CWE-122)",
            "summary": "Premiere Pro is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00337,
            "epssPercentile": 0.26583,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "26.3; 25.6.6",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48270",
            "title": "Premiere Pro | Out-of-bounds Write (CWE-787)",
            "summary": "Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.1716,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "26.3; 25.6.6",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48308",
            "title": "Premiere Pro | Improper Input Validation (CWE-20)",
            "summary": "Premiere Pro is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00242,
            "epssPercentile": 0.15314,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "26.3; 25.6.6",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48369",
            "title": "Premiere Pro | Out-of-bounds Write (CWE-787)",
            "summary": "Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17162,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "26.3; 25.6.6",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update path and test the fixed release against managed plug-ins, workflows and file formats before broad deployment."
      ],
      "data_gaps": [
        "Restart requirements are not asserted unless the reviewed bulletin states them explicitly."
      ],
      "provenance": [
        {
          "field": "advisory_identity_and_release",
          "source_path": "adobe-bulletin/solution",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships",
          "source_path": "adobe-bulletin/vulnerability-details",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Initial APSB26-76 publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The bulletin identity, release date, fixed versions, platforms, vendor signals and complete public CVE list were generated from the official Adobe bulletin and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-48369",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-07-3747367",
      "slug": "sap-2026-07-3747367",
      "cycle_id": "2026-07",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3747367",
      "title": "Assess and apply SAP security advisory 3747367",
      "source_title": "[CVE-2026-44747] Memory Corruption vulnerability in SAP NetWeaver Application Server ABAP Product - SAP NetWeaver Application Server ABAP | Version(s) - KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, KERNEL 7.22, 7.53. 7.54, 7.77, 7.89, 7.93, 9.16, 9.18, 9.19, 9.20",
      "source_url": "https://me.sap.com/notes/3747367",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "SAP NetWeaver Application Server ABAP",
      "platform": "SAP",
      "release_version": "KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, KERNEL 7.22, 7.53. 7.54, 7.77, 7.89, 7.93, 9.16, 9.18, 9.19, 9.20",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 9.9",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3747367 in its 2026-07 Security Patch Day release for SAP NetWeaver Application Server ABAP. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-44747"
        ],
        "details": [
          {
            "id": "CVE-2026-44747",
            "title": "Memory Corruption vulnerability in SAP NetWeaver Application Server ABAP",
            "summary": "SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system unavailability. This has high impact on confidentiality, integrity, and availability of the application.",
            "score": 9.9,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00564,
            "epssPercentile": 0.44794,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.9,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-44747",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-07-3720138",
      "slug": "sap-2026-07-3720138",
      "cycle_id": "2026-07",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3720138",
      "title": "Assess and apply SAP security advisory 3720138",
      "source_title": "[CVE-2026-27690] HTTP Request Smuggling in SAP Approuter Library - SAP Approuter | Version(s) - SAP Approuter node.js package < 20.10.0",
      "source_url": "https://me.sap.com/notes/3720138",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "SAP product listed in the Patch Day bulletin",
      "platform": "SAP",
      "release_version": "SAP Approuter node.js package < 20.10.0",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 9.1",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3720138 in its 2026-07 Security Patch Day release for SAP product listed in the Patch Day bulletin. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-27690"
        ],
        "details": [
          {
            "id": "CVE-2026-27690",
            "title": "HTTP Request Smuggling in SAP Approuter",
            "summary": "Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the exposure of user responses and cause the system to become unavailable. This leads to a high impact on confidentiality and availability.",
            "score": 9.1,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00682,
            "epssPercentile": 0.50196,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-27690",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-07-3753495",
      "slug": "sap-2026-07-3753495",
      "cycle_id": "2026-07",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3753495",
      "title": "Assess and apply SAP security advisory 3753495",
      "source_title": "[CVE-2026-44761] Insecure Sample Credentials in SAP Commerce Cloud Product - SAP Commerce Cloud | Version(s) - HY_COM 2205, COM_CLOUD 2211, 2211-JDK21",
      "source_url": "https://me.sap.com/notes/3753495",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "SAP Commerce Cloud",
      "platform": "SAP",
      "release_version": "HY_COM 2205, COM_CLOUD 2211, 2211-JDK21",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 9.1",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3753495 in its 2026-07 Security Patch Day release for SAP Commerce Cloud. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-44761"
        ],
        "details": [
          {
            "id": "CVE-2026-44761",
            "title": "Insecure Sample Credentials in SAP Commerce Cloud",
            "summary": "SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an unauthenticated attacker could use these well-known credentials to obtain a valid access token and invoke certain APIs to read and modify data. Successful exploitation results in high impact on confidentiality and inte",
            "score": 9.1,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00498,
            "epssPercentile": 0.40881,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-44761",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-07-3727078",
      "slug": "sap-2026-07-3727078",
      "cycle_id": "2026-07",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3727078",
      "title": "Assess and apply SAP security advisory 3727078",
      "source_title": "Update to Security Note released on June 2026 Patch Day: | | [CVE-2026-40128] Directory Traversal vulnerability in SAP NetWeaver Application Server Java (Web Container) Product - SAP NetWeaver Application Server Java (Web Container) | Version(s) - ENGINEAPI 7.50",
      "source_url": "https://me.sap.com/notes/3727078",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "revised",
      "product": "SAP NetWeaver Application Server Java (Web Container)",
      "platform": "SAP",
      "release_version": "ENGINEAPI 7.50",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 9.0",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3727078 in its 2026-07 Security Patch Day release for SAP NetWeaver Application Server Java (Web Container). The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-40128"
        ],
        "details": [
          {
            "id": "CVE-2026-40128",
            "title": "Directory Traversal vulnerability in SAP NetWeaver Application Server Java (Web Container)",
            "summary": "SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon request that manipulates file inclusion parameters, enabling path traversal and processing of the included file. Processing the included file could allow the attacker to view or modify sensitive information or render any part of the local system unavailable.",
            "score": 9,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00454,
            "epssPercentile": 0.37987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-40128",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-07-3758101",
      "slug": "sap-2026-07-3758101",
      "cycle_id": "2026-07",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3758101",
      "title": "Assess and apply SAP security advisory 3758101",
      "source_title": "[CVE-2026-40860] Multiple vulnerabilities in Apache Camel within SAP Integration Suite (Edge Integration Cell) | Related CVEs - CVE-2026-40453, CVE-2026-33454 Product - SAP Integration Suite (Edge Integration Cell) | Version(s) - SAP Integration Suite (Edge Integration Cell) < 8.43.11",
      "source_url": "https://me.sap.com/notes/3758101",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "SAP Integration Suite (Edge Integration Cell)",
      "platform": "SAP",
      "release_version": "SAP Integration Suite (Edge Integration Cell) < 8.43.11",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "High; CVSS 8.8",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3758101 in its 2026-07 Security Patch Day release for SAP Integration Suite (Edge Integration Cell). The public bulletin links 3 CVEs; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 3,
        "ids": [
          "CVE-2026-33454",
          "CVE-2026-40453",
          "CVE-2026-40860"
        ],
        "details": [
          {
            "id": "CVE-2026-33454",
            "title": "Apache Camel: Inbound Header Filter Missing in MailHeaderFilterStrategy Allows Remote Code Execution via MIME Header Injection (CVE-2025-30177 Variant)",
            "summary": "The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the component (MailHeaderFilterStrategy) only filters the 'out' direction via setOutFilterStartsWith, while it does not configure the 'in' direction via setInFilterStartsWith. As a result, when a Camel application consumes mail through camel-mail (for example via from(\\\"imap://...\\\") or from(\\\"pop3://..",
            "score": 9.4,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00621,
            "epssPercentile": 0.47565,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-40453",
            "title": "Apache Camel JMS, Apache Camel CoAP, Apache Camel Google PubSub: Incomplete fix for CVE-2025-27636 in non-HTTP HeaderFilterStrategies (camel-jms, camel-sjms, camel-coap, camel-google-pubsub) allows case-variant header injection",
            "summary": "The fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CAmelExecCommandExecutable' are filtered out alongside 'CamelExecCommandExecutable'. The same setLowerCase(true) call was not applied to five non-HTTP HeaderFilterStrategy implementations: JmsHeaderFilterStrategy and ClassicJmsHeaderFilterStrategy in camel-jms, SjmsHeaderFilterStrategy in camel-s",
            "score": 9.9,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01556,
            "epssPercentile": 0.73526,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-40860",
            "title": "Apache Camel: Unsafe Deserialization of JMS ObjectMessage in camel-jms, camel-sjms, camel-sjms2 and camel-amqp",
            "summary": "JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessage values via javax.jms.ObjectMessage.getObject() without applying any ObjectInputFilter, class allowlist or class denylist. Because this code path is reached whenever the mapJmsMessage option is enabled (the default) and Camel acts as a JMS consumer, an attacker able to",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01226,
            "epssPercentile": 0.66851,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.9,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-40453",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-07-3692165",
      "slug": "sap-2026-07-3692165",
      "cycle_id": "2026-07",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3692165",
      "title": "Assess and apply SAP security advisory 3692165",
      "source_title": "[CVE-2026-0487] DLL Hijacking vulnerability in SAProuter on Microsoft Windows Product - SAProuter on Microsoft Windows | Version(s) - KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, SAP_ROUTER 7.53, 7.54, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 9.16, 9.17, 9.18",
      "source_url": "https://me.sap.com/notes/3692165",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "SAProuter on Microsoft Windows",
      "platform": "SAP",
      "release_version": "KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, SAP_ROUTER 7.53, 7.54, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 9.16, 9.17, 9.18",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "High; CVSS 8.4",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3692165 in its 2026-07 Security Patch Day release for SAProuter on Microsoft Windows. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-0487"
        ],
        "details": [
          {
            "id": "CVE-2026-0487",
            "title": "DLL Hijacking vulnerability in SAProuter on Microsoft Windows",
            "summary": "SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from an untrusted location, allowing them to execute malicious code on the system. This could enable the attacker to hijack the DLL loading process and achieve arbitrary code execution. This has high impact on confidentiality, integrity and availability of the system.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0021,
            "epssPercentile": 0.11149,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.4,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-0487",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-07-3748227",
      "slug": "sap-2026-07-3748227",
      "cycle_id": "2026-07",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3748227",
      "title": "Assess and apply SAP security advisory 3748227",
      "source_title": "[CVE-2026-44752] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server Java(Configuration Wizard) Product - SAP NetWeaver Application Server Java(Configuration Wizard) | Version(s) - LMCTC 7.50",
      "source_url": "https://me.sap.com/notes/3748227",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "SAP NetWeaver Application Server Java(Configuration Wizard)",
      "platform": "SAP",
      "release_version": "LMCTC 7.50",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "High; CVSS 8.2",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3748227 in its 2026-07 Security Patch Day release for SAP NetWeaver Application Server Java(Configuration Wizard). The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-44752"
        ],
        "details": [
          {
            "id": "CVE-2026-44752",
            "title": "Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server Java(Configuration Wizard)",
            "summary": "SAP NetWeaver Application Server Java allows an unauthenticated attacker to inject malicious JavaScript through crafted URLs. When a victim accesses such a URL, the script executes in the user's browser, allowing the attacker to access sensitive session information and modify non-sensitive data displayed in the client�s browser. This results in a high impact on confidentiality, low impact on integrity with no impact ",
            "score": 8.2,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0036,
            "epssPercentile": 0.29111,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.2,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-44752",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-07-3741519",
      "slug": "sap-2026-07-3741519",
      "cycle_id": "2026-07",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3741519",
      "title": "Assess and apply SAP security advisory 3741519",
      "source_title": "[CVE-2026-44745] Open Redirect vulnerability in SAP Approuter Library - SAP Approuter | Version(s) - SAP Approuter node.js package < 21.2.0",
      "source_url": "https://me.sap.com/notes/3741519",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "SAP product listed in the Patch Day bulletin",
      "platform": "SAP",
      "release_version": "SAP Approuter node.js package < 21.2.0",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "High; CVSS 8.1",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3741519 in its 2026-07 Security Patch Day release for SAP product listed in the Patch Day bulletin. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-44745"
        ],
        "details": [
          {
            "id": "CVE-2026-44745",
            "title": "Open Redirect vulnerability in SAP Approuter",
            "summary": "SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked by a victim, could lead to unauthorized access. Successful exploitation results in a high impact to the confidentiality and integrity with no impact on the availability of the application.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00466,
            "epssPercentile": 0.3873,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-44745",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-07-3763800",
      "slug": "sap-2026-07-3763800",
      "cycle_id": "2026-07",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3763800",
      "title": "Assess and apply SAP security advisory 3763800",
      "source_title": "[Multiple CVEs] Multiple vulnerabilities in Apache Tomcat within SAP Commerce Cloud | CVEs - CVE-2026-43512, CVE-2026-41293, CVE-2026-43515 Product - SAP Commerce Cloud | Version(s) - HY_COM 2205, COM_CLOUD 2211, 2211-JDK21",
      "source_url": "https://me.sap.com/notes/3763800",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "SAP Commerce Cloud",
      "platform": "SAP",
      "release_version": "HY_COM 2205, COM_CLOUD 2211, 2211-JDK21",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "High; CVSS 8.1",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3763800 in its 2026-07 Security Patch Day release for SAP Commerce Cloud. The public bulletin links 3 CVEs; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 3,
        "ids": [
          "CVE-2026-41293",
          "CVE-2026-43512",
          "CVE-2026-43515"
        ],
        "details": [
          {
            "id": "CVE-2026-41293",
            "title": "Apache Tomcat: HTTP/2 request headers not validated",
            "summary": "Improper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 10.0.0-M1 through 10.0.27. Older, end of support versions may also be affected. Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01563,
            "epssPercentile": 0.73627,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-43512",
            "title": "Apache Tomcat: Digest authenticator will authenticate any unknown user",
            "summary": "DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from before 7.0.0. Older unsupported versions any also be affect Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01233,
            "epssPercentile": 0.6704,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-43515",
            "title": "Apache Tomcat: Security constraints not correctly applied",
            "summary": "Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.",
            "score": 9.1,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01136,
            "epssPercentile": 0.64401,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-43512",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-07-3773304",
      "slug": "sap-2026-07-3773304",
      "cycle_id": "2026-07",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3773304",
      "title": "Assess and apply SAP security advisory 3773304",
      "source_title": "[CVE-2026-58233] Remote Code Execution vulnerability in SAP Change and Transport System Attach Tool (ctsattach) Product - SAP Change and Transport System Attach Tool (ctsattach) | Version(s) - CTS_UPLOAD_CLT 1",
      "source_url": "https://me.sap.com/notes/3773304",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "SAP Change and Transport System Attach Tool (ctsattach)",
      "platform": "SAP",
      "release_version": "CTS_UPLOAD_CLT 1",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "High; CVSS 7.6",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3773304 in its 2026-07 Security Patch Day release for SAP Change and Transport System Attach Tool (ctsattach). The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-58233"
        ],
        "details": [
          {
            "id": "CVE-2026-58233",
            "title": "Remote Code Execution vulnerability in SAP Change and Transport System Attach Tool (ctsattach)",
            "summary": "SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted archive file which, when processed by the application�s library, can trigger insecure deserialization and lead to remote code execution (RCE) on the system. Successful exploitation requires a victim to process the malicious archive, enabling the attacker to execute the RCE and extract sensitive infor",
            "score": 7.6,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00556,
            "epssPercentile": 0.44348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.6,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-58233",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-07-3746678",
      "slug": "sap-2026-07-3746678",
      "cycle_id": "2026-07",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3746678",
      "title": "Assess and apply SAP security advisory 3746678",
      "source_title": "[CVE-2026-44759] Cross Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal Product - SAP NetWeaver Enterprise Portal | Version(s) - EP-RUNTIME 7.50",
      "source_url": "https://me.sap.com/notes/3746678",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "SAP NetWeaver Enterprise Portal",
      "platform": "SAP",
      "release_version": "EP-RUNTIME 7.50",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 6.1",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3746678 in its 2026-07 Security Patch Day release for SAP NetWeaver Enterprise Portal. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-44759"
        ],
        "details": [
          {
            "id": "CVE-2026-44759",
            "title": "Cross Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal",
            "summary": "SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject malicious scripts into a URL parameter. The scripts are reflected in the server response and executed in a user's browser when the crafted URL is visited, leading to theft of session information, manipulation of portal content, or user redirection, resulting in a low impact on the application's confidentiality and integrity, with no impact o",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00286,
            "epssPercentile": 0.20831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 6.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-44759",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-07-ghsa-p8gx-753q-v89p",
      "slug": "sap-2026-07-ghsa-p8gx-753q-v89p",
      "cycle_id": "2026-07",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "GHSA-p8gx-753q-v89p",
      "title": "Assess and apply SAP security advisory GHSA-p8gx-753q-v89p",
      "source_title": "[CVE-2026-44767] Allowlist Bypass in setThemeRoot() Enables Cross-Origin CSS Injection Library - ui5/webcomponents-base | Version(s) - ui5 webcomponents-base < 2.21.0",
      "source_url": "https://github.com/UI5/webcomponents/security/advisories/GHSA-p8gx-753q-v89p",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "SAP product listed in the Patch Day bulletin",
      "platform": "SAP",
      "release_version": "ui5 webcomponents-base < 2.21.0",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 6.1",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists GHSA-p8gx-753q-v89p in its 2026-07 Security Patch Day release for SAP product listed in the Patch Day bulletin. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-44767"
        ],
        "details": [
          {
            "id": "CVE-2026-44767",
            "title": "Allowlist Bypass in setThemeRoot() Enables Cross-Origin CSS Injection",
            "summary": "setThemeRoot() failed to enforce the sap-allowed-theme-origins allowlist. An attacker-controlled absolute cross-origin URL could be stored and used directly to construct a <link rel=stylesheet> element, even when no <meta name=sap-allowed-theme-origins> tag was present in the document. The same bypass was reachable via the ?sap-themeRoot URL parameter.Exploitation requires attacker-influenced input (e.g., a URL query",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00285,
            "epssPercentile": 0.20753,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 6.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-44767",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-07-3537373",
      "slug": "sap-2026-07-3537373",
      "cycle_id": "2026-07",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3537373",
      "title": "Assess and apply SAP security advisory 3537373",
      "source_title": "[CVE-2026-44769] SQL Injection vulnerability in SAP S/4HANA Project Management (PPM-PRO) Product - SAP S/4HANA Project Management (PPM-PRO) | Version(s) - SAP_APPL 600, 602, 603, 604, 605, 606, 617, 618, S4CORE 102, 103, 104, 105, 106, 107, 108, CPRXRPM 400, 450_700, 500_702, 610_740",
      "source_url": "https://me.sap.com/notes/3537373",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "SAP S/4HANA Project Management (PPM-PRO)",
      "platform": "SAP",
      "release_version": "SAP_APPL 600, 602, 603, 604, 605, 606, 617, 618, S4CORE 102, 103, 104, 105, 106, 107, 108, CPRXRPM 400, 450_700, 500_702, 610_740",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 5.5",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3537373 in its 2026-07 Security Patch Day release for SAP S/4HANA Project Management (PPM-PRO). The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-44769"
        ],
        "details": [
          {
            "id": "CVE-2026-44769",
            "title": "SQL Injection vulnerability in SAP S/4HANA Project Management (PPM-PRO)",
            "summary": "SAP S/4HANA application Project Management (PPM-PRO) allows an attacker with high privileges to execute crafted database queries, exposing the backend database. This results in low impact on confidentiality, with no impact on integrity and availability of the application.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00308,
            "epssPercentile": 0.23252,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 5.5,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-44769",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-07-3754659",
      "slug": "sap-2026-07-3754659",
      "cycle_id": "2026-07",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3754659",
      "title": "Assess and apply SAP security advisory 3754659",
      "source_title": "[CVE-2026-44760] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (applications based on Business Server Pages) Product - SAP NetWeaver Application Server ABAP (applications based on Business Server Pages) | Version(s) - SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 816, SAP_BASIS 918, SAP_BASIS 919, SAP_BASIS 920",
      "source_url": "https://me.sap.com/notes/3754659",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "SAP NetWeaver Application Server ABAP (applications based on Business Server Pages)",
      "platform": "SAP",
      "release_version": "SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 816, SAP_BASIS 918, SAP_BASIS 919, SAP_BASIS 920",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 4.7",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3754659 in its 2026-07 Security Patch Day release for SAP NetWeaver Application Server ABAP (applications based on Business Server Pages). The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-44760"
        ],
        "details": [
          {
            "id": "CVE-2026-44760",
            "title": "Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (applications based on Business Server Pages)",
            "summary": "Due to a Cross-Site Scripting (XSS) vulnerability, applications based on Business Server Pages framework in SAP NetWeaver Application Server ABAP reflects unsanitized input into the HTTP response which allows an attacker to inject and execute arbitrary JavaScript code under certain conditions. Successful exploitation could allow the attacker to steal session information, perform authenticated actions on behalf of the",
            "score": 4.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00227,
            "epssPercentile": 0.13395,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 4.7,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-44760",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-07-3515598",
      "slug": "sap-2026-07-3515598",
      "cycle_id": "2026-07",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3515598",
      "title": "Assess and apply SAP security advisory 3515598",
      "source_title": "[CVE-2026-44771] Missing Authorization check in SAP S/4HANA (Draft operation) Product - SAP S/4HANA (Draft operation) | Version(s) - S4CORE 108",
      "source_url": "https://me.sap.com/notes/3515598",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "SAP S/4HANA (Draft operation)",
      "platform": "SAP",
      "release_version": "S4CORE 108",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 4.3",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3515598 in its 2026-07 Security Patch Day release for SAP S/4HANA (Draft operation). The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-44771"
        ],
        "details": [
          {
            "id": "CVE-2026-44771",
            "title": "Missing Authorization check in SAP S/4HANA (Draft operation)",
            "summary": "SAP S/4HANA Draft operation does not perform necessary authorization checks for an authenticated user, a restricted user could access information within the entity resulting in escalation of privileges. This results in low impact on confidentiality, with no impact on integrity and availability of the application.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00281,
            "epssPercentile": 0.20297,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 4.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-44771",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-07-3713902",
      "slug": "sap-2026-07-3713902",
      "cycle_id": "2026-07",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3713902",
      "title": "Assess and apply SAP security advisory 3713902",
      "source_title": "[CVE-2026-44770] Missing Authorization check in SAP S/4 HANA (Create Single Payment) Product - SAP S/4 HANA (Create Single Payment) | Version(s) - S4CORE 102, 103, 104, 105, 106, 107, 108, 109",
      "source_url": "https://me.sap.com/notes/3713902",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "SAP S/4 HANA (Create Single Payment)",
      "platform": "SAP",
      "release_version": "S4CORE 102, 103, 104, 105, 106, 107, 108, 109",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 4.3",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3713902 in its 2026-07 Security Patch Day release for SAP S/4 HANA (Create Single Payment). The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-44770"
        ],
        "details": [
          {
            "id": "CVE-2026-44770",
            "title": "Missing Authorization check in SAP S/4 HANA (Create Single Payment)",
            "summary": "SAP Create Single Payment does not perform necessary authorization checks for an authenticated user, a restricted user could access specific entity set keys resulting in disclosure of information. This has low impact on confidentiality, with no impact on integrity and availability of the application.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00281,
            "epssPercentile": 0.20296,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 4.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-44770",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-07-3682699",
      "slug": "sap-2026-07-3682699",
      "cycle_id": "2026-07",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3682699",
      "title": "Assess and apply SAP security advisory 3682699",
      "source_title": "Update to Security Note released on June 2026 Patch Day: | | [CVE-2026-24315] Path Traversal Vulnerability in SAP Fiori (launchpad) | | Product - SAP Fiori (launchpad) | Version(s) - SAP_UI 754, 755, 756, 757, 758, 816",
      "source_url": "https://me.sap.com/notes/3682699",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "revised",
      "product": "SAP Fiori (launchpad)",
      "platform": "SAP",
      "release_version": "SAP_UI 754, 755, 756, 757, 758, 816",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 4.2",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3682699 in its 2026-07 Security Patch Day release for SAP Fiori (launchpad). The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-24315"
        ],
        "details": [
          {
            "id": "CVE-2026-24315",
            "title": "Path Traversal Vulnerability in SAP Fiori (launchpad)",
            "summary": "SAP Fiori Launchpad allows attackers to craft malicious URLs that triggers arbitrary service calls on the Fiori domain, this when opened by the user could compromise accounts by stealing user credentials. Successful exploitation requires adversaries to possess advanced knowledge of the system causing low impact on Confidentiality and Integrity. Availability of the system is no impacted.",
            "score": 4.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00174,
            "epssPercentile": 0.07009,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 4.2,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-24315",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-07-3155685",
      "slug": "sap-2026-07-3155685",
      "cycle_id": "2026-07",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3155685",
      "title": "Assess and apply SAP security advisory 3155685",
      "source_title": "[CVE-2026-44768] Security misconfiguration in SAP CRM (WebClient UI) Product - SAP CRM (WebClient UI) | Version(s) - S4FND 104, 105, 106",
      "source_url": "https://me.sap.com/notes/3155685",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "SAP CRM (WebClient UI)",
      "platform": "SAP",
      "release_version": "S4FND 104, 105, 106",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 4.1",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3155685 in its 2026-07 Security Patch Day release for SAP CRM (WebClient UI). The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-44768"
        ],
        "details": [
          {
            "id": "CVE-2026-44768",
            "title": "Security misconfiguration in SAP CRM (WebClient UI)",
            "summary": "SAP CRM WebClient UI allows an attacker to inject and execute malicious scripts in the context of the application due to the absence of a Content Security Policy (CSP) configuration for certain restrictive directives. This vulnerability has a low impact on the integrity of the application. Confidentiality and availability are not impacted.",
            "score": 4.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00259,
            "epssPercentile": 0.17456,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 4.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-44768",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-07-3732522",
      "slug": "sap-2026-07-3732522",
      "cycle_id": "2026-07",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3732522",
      "title": "Assess and apply SAP security advisory 3732522",
      "source_title": "[CVE-2026-44753] Information Disclosure vulnerability in SAP HANA Extended Application Services classic model (User Self Service) Product - SAP HANA Extended Application Services classic model (User Self Service) | Version(s) - HDB 2.00",
      "source_url": "https://me.sap.com/notes/3732522",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "active",
      "product": "SAP HANA Extended Application Services classic model (User Self Service)",
      "platform": "SAP",
      "release_version": "HDB 2.00",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Low; CVSS 3.7",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3732522 in its 2026-07 Security Patch Day release for SAP HANA Extended Application Services classic model (User Self Service). The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-44753"
        ],
        "details": [
          {
            "id": "CVE-2026-44753",
            "title": "Information Disclosure vulnerability in SAP HANA Extended Application Services classic model (User Self Service)",
            "summary": "SAP HANA Database (user self service tools) allows an unauthenticated user to send specially crafted requests that produce distinguishable responses, enabling enumeration of valid user accounts and email addresses. Successful exploitation could allow the attacker to enumerate valid user accounts, resulting in low impact on confidentiality, with no impact on integrity and availability of the application.",
            "score": 3.7,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00346,
            "epssPercentile": 0.27557,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 3.7,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-44753",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-07-3726899",
      "slug": "sap-2026-07-3726899",
      "cycle_id": "2026-07",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3726899",
      "title": "Assess and apply SAP security advisory 3726899",
      "source_title": "Update to Security Note released on June 2026 Patch Day: | | [CVE-2025-68161] Potential vulnerability in Apache Log4j library used by SAP NetWeaver AS Java Product - SAP NetWeaver AS Java | Version(s) – SERVERCORE 7.50, CORE-TOOLS 7.50, J2EE-APPS 7.50",
      "source_url": "https://me.sap.com/notes/3726899",
      "published_at": "2026-07-14",
      "updated_at": "2026-07-14",
      "status": "revised",
      "product": "SAP NetWeaver AS Java",
      "platform": "SAP",
      "release_version": "SERVERCORE 7.50, CORE-TOOLS 7.50, J2EE-APPS 7.50",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Low; CVSS 3.3",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3726899 in its 2026-07 Security Patch Day release for SAP NetWeaver AS Java. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-68161"
        ],
        "details": [
          {
            "id": "CVE-2025-68161",
            "title": "Apache Log4j Core: Missing TLS hostname verification in Socket appender",
            "summary": "The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostname verification of the peer certificate, even when the verifyHostName https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName configuration attribute or the log4j2.sslVerifyHostName https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostNa",
            "score": 6.3,
            "version": "4.0",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.00816,
            "epssPercentile": 0.54758,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Medium technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-07-14",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 6.3,
        "max_cvss_version": "4.0",
        "max_cvss_cve": "CVE-2025-68161",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-apps-msrc-2026-08-apps-release-notes-app-installer",
      "slug": "microsoft-2026-08-apps-msrc-2026-08-apps-release-notes-app-installer",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-08-apps-release-notes",
      "title": "Deploy Microsoft Apps update for App Installer",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://github.com/microsoft/winget-cli/releases/download/v1.29.280/Microsoft.DesktopAppInstaller_8wekyb3d8bbwe.msixbundle",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "App Installer",
      "platform": "Apps",
      "release_version": "1.29.280",
      "action_type": "deploy-patch",
      "restart_required": "no",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for App Installer.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-68821"
        ],
        "details": [
          {
            "id": "CVE-2026-68821",
            "title": "Windows Package Manager Elevation of Privilege Vulnerability",
            "summary": "Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0027,
            "epssPercentile": 0.18986,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-68821",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "The reviewed source does not require a restart.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-azure-msrc-2026-08-azure-release-notes-azure-monitor-agent-linux-extension",
      "slug": "microsoft-2026-08-azure-msrc-2026-08-azure-release-notes-azure-monitor-agent-linux-extension",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-08-azure-release-notes",
      "title": "Deploy Microsoft Azure update for Azure Monitor Agent Linux Extension",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://learn.microsoft.com/en-us/azure/azure-monitor/agents/azure-monitor-agent-manage?tabs=azure-portal",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Azure Monitor Agent Linux Extension",
      "platform": "Azure",
      "release_version": "1.43",
      "action_type": "deploy-patch",
      "restart_required": "no",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Monitor Agent Linux Extension.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-47299"
        ],
        "details": [
          {
            "id": "CVE-2026-47299",
            "title": "Azure Monitor Agent Elevation of Privilege Vulnerability",
            "summary": "Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network.",
            "score": 7.2,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00939,
            "epssPercentile": 0.58629,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.2,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-47299",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "The reviewed source does not require a restart.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-azure-msrc-2026-08-azure-release-notes-microsoft-hpc-pack-2019",
      "slug": "microsoft-2026-08-azure-msrc-2026-08-azure-release-notes-microsoft-hpc-pack-2019",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-08-azure-release-notes",
      "title": "Deploy Microsoft Azure update for Microsoft HPC Pack 2019",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://www.microsoft.com/en-us/download/details.aspx?id=108779",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft HPC Pack 2019",
      "platform": "Azure",
      "release_version": "6.3.8359",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft HPC Pack 2019.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-59124"
        ],
        "details": [
          {
            "id": "CVE-2026-59124",
            "title": "Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01684,
            "epssPercentile": 0.75459,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-59124",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-azure-msrc-2026-08-azure-release-notes-microsoft-entra-connect",
      "slug": "microsoft-2026-08-azure-msrc-2026-08-azure-release-notes-microsoft-entra-connect",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-08-azure-release-notes",
      "title": "Deploy Microsoft Azure update for Microsoft Entra Connect",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://entra.microsoft.com/#view/Microsoft_AAD_Connect_Provisioning/AADConnectMenuBlade/~/GetStarted",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft Entra Connect",
      "platform": "Azure",
      "release_version": "2.6.84.0",
      "action_type": "deploy-patch",
      "restart_required": "no",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Entra Connect.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-65673"
        ],
        "details": [
          {
            "id": "CVE-2026-65673",
            "title": "Microsoft Entra Connect Elevation of Privilege Vulnerability",
            "summary": "Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Entra Connect Sync allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00322,
            "epssPercentile": 0.24874,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-65673",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "The reviewed source does not require a restart.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-azure-msrc-2026-08-azure-release-notes-azure-cyclecloud-8-9-2",
      "slug": "microsoft-2026-08-azure-msrc-2026-08-azure-release-notes-azure-cyclecloud-8-9-2",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-08-azure-release-notes",
      "title": "Deploy Microsoft Azure update for Azure CycleCloud 8.9.2",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://learn.microsoft.com/en-us/azure/cyclecloud/how-to/upgrade-and-migrate?view=cyclecloud-8",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Azure CycleCloud 8.9.2",
      "platform": "Azure",
      "release_version": "8.9.2",
      "action_type": "deploy-patch",
      "restart_required": "no",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure CycleCloud 8.9.2.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-65806"
        ],
        "details": [
          {
            "id": "CVE-2026-65806",
            "title": "Azure CycleCloud Information Disclosure Vulnerability",
            "summary": "Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00577,
            "epssPercentile": 0.45437,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 6.5,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-65806",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "The reviewed source does not require a restart.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-azure-msrc-2026-08-azure-release-notes-azure-cyclecloud-8-9-1",
      "slug": "microsoft-2026-08-azure-msrc-2026-08-azure-release-notes-azure-cyclecloud-8-9-1",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-08-azure-release-notes",
      "title": "Deploy Microsoft Azure update for Azure CycleCloud 8.9.1",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://learn.microsoft.com/en-us/azure/cyclecloud/how-to/upgrade-and-migrate?view=cyclecloud-8",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Azure CycleCloud 8.9.1",
      "platform": "Azure",
      "release_version": "8.9.1",
      "action_type": "deploy-patch",
      "restart_required": "no",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure CycleCloud 8.9.1.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-70340"
        ],
        "details": [
          {
            "id": "CVE-2026-70340",
            "title": "Azure CycleCloud Elevation of Privilege Vulnerability",
            "summary": "Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00603,
            "epssPercentile": 0.46689,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-70340",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "The reviewed source does not require a restart.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-browser-msrc-2026-08-browser-release-notes-microsoft-edge-chromium-based",
      "slug": "microsoft-2026-08-browser-msrc-2026-08-browser-release-notes-microsoft-edge-chromium-based",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-08-browser-release-notes",
      "title": "Deploy Microsoft Browser update for Microsoft Edge (Chromium-based)",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://msrc.microsoft.com/update-guide/releaseNote/2026-Aug",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft Edge (Chromium-based)",
      "platform": "Browser",
      "release_version": "151.0.4129.78",
      "action_type": "deploy-patch",
      "restart_required": "no",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 39 linked CVEs for Microsoft Edge (Chromium-based).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 39,
        "ids": [
          "CVE-2026-19137",
          "CVE-2026-19138",
          "CVE-2026-19139",
          "CVE-2026-19140",
          "CVE-2026-19142",
          "CVE-2026-19144",
          "CVE-2026-19145",
          "CVE-2026-19146",
          "CVE-2026-19147",
          "CVE-2026-19148",
          "CVE-2026-19149",
          "CVE-2026-19150",
          "CVE-2026-19151",
          "CVE-2026-19152",
          "CVE-2026-19153",
          "CVE-2026-19155",
          "CVE-2026-19156",
          "CVE-2026-19157",
          "CVE-2026-19158",
          "CVE-2026-19159",
          "CVE-2026-19160",
          "CVE-2026-19161",
          "CVE-2026-19162",
          "CVE-2026-19163",
          "CVE-2026-19164",
          "CVE-2026-19165",
          "CVE-2026-19166",
          "CVE-2026-19167",
          "CVE-2026-19168",
          "CVE-2026-19169",
          "CVE-2026-19170",
          "CVE-2026-19171",
          "CVE-2026-19172",
          "CVE-2026-19173",
          "CVE-2026-19174",
          "CVE-2026-19175",
          "CVE-2026-19176",
          "CVE-2026-19177",
          "CVE-2026-70339"
        ],
        "details": [
          {
            "id": "CVE-2026-19137",
            "title": "Google Chrome - Use After Free",
            "summary": "Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
            "score": 8.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00447,
            "epssPercentile": 0.37477,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-19138",
            "title": "Google Chrome - Heap-based Buffer Overflow",
            "summary": "Heap buffer overflow in CrashReporting in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
            "score": 8.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00357,
            "epssPercentile": 0.28816,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-19139",
            "title": "Race in CredentialProvider in Google Chrome on Windows prior to 151.0.7922.109 allowed a local attacker to perform OS-level privilege escalation via a malicious file",
            "summary": "Race in CredentialProvider in Google Chrome on Windows prior to 151.0.7922.109 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)",
            "score": 7.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00129,
            "epssPercentile": 0.02798,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-19140",
            "title": "Google Chrome - Use After Free",
            "summary": "Use after free in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
            "score": 8.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00324,
            "epssPercentile": 0.25021,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-19142",
            "title": "Google Chrome - Use After Free",
            "summary": "Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00417,
            "epssPercentile": 0.34886,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-19144",
            "title": "Use after free in HTML in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page",
            "summary": "Use after free in HTML in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00358,
            "epssPercentile": 0.28826,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-19145",
            "title": "Use after free in Translate in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page",
            "summary": "Use after free in Translate in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00418,
            "epssPercentile": 0.35048,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-19146",
            "title": "Google Chrome - Use of Uninitialized Variable",
            "summary": "Uninitialized Use in GPU in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00349,
            "epssPercentile": 0.27911,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-19147",
            "title": "Google Chrome - Use After Free",
            "summary": "Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
            "score": 8.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00324,
            "epssPercentile": 0.2502,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-19148",
            "title": "Google Chrome - Out-of-bounds Write",
            "summary": "Out of bounds write in GPU in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
            "score": 8.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00324,
            "epssPercentile": 0.2502,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-19149",
            "title": "Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page",
            "summary": "Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
            "score": 9.6,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00493,
            "epssPercentile": 0.40614,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-19150",
            "title": "Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page",
            "summary": "Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00538,
            "epssPercentile": 0.43393,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-19151",
            "title": "Use after free in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page",
            "summary": "Use after free in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00538,
            "epssPercentile": 0.43392,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-19152",
            "title": "Google Chrome - Protection Mechanism Failure",
            "summary": "Insufficient policy enforcement in Navigation in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
            "score": 8.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00337,
            "epssPercentile": 0.26542,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-19153",
            "title": "Google Chrome - Improper Input Validation",
            "summary": "Insufficient validation of untrusted input in Workers in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00353,
            "epssPercentile": 0.28278,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-19155",
            "title": "Google Chrome - Use After Free",
            "summary": "Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
            "score": 8.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00324,
            "epssPercentile": 0.25021,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-19156",
            "title": "Google Chrome - Heap-based Buffer Overflow",
            "summary": "Heap buffer overflow in Base in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00256,
            "epssPercentile": 0.17105,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-19157",
            "title": "Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page",
            "summary": "Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
            "score": 9.6,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00384,
            "epssPercentile": 0.31545,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-19158",
            "title": "Google Chrome - Use After Free",
            "summary": "Use after free in Views in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00434,
            "epssPercentile": 0.36428,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-19159",
            "title": "Google Chrome - Use After Free",
            "summary": "Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00417,
            "epssPercentile": 0.34886,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-19160",
            "title": "Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page",
            "summary": "Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
            "score": 3.1,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00383,
            "epssPercentile": 0.31472,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-19161",
            "title": "Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page",
            "summary": "Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
            "score": 3.1,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0032,
            "epssPercentile": 0.24628,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-19162",
            "title": "Out of bounds write in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page",
            "summary": "Out of bounds write in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00418,
            "epssPercentile": 0.35048,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-19163",
            "title": "Google Chrome - Use After Free",
            "summary": "Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
            "score": 8.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00324,
            "epssPercentile": 0.25021,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-19164",
            "title": "Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page",
            "summary": "Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
            "score": 9.6,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00358,
            "epssPercentile": 0.28827,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-19165",
            "title": "Google Chrome - Use After Free",
            "summary": "Use after free in Extensions in Google Chrome prior to 151.0.7922.109 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: High)",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00263,
            "epssPercentile": 0.17918,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-19166",
            "title": "Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page",
            "summary": "Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
            "score": 9.6,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00424,
            "epssPercentile": 0.35567,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-19167",
            "title": "Integer overflow in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page",
            "summary": "Integer overflow in GPU in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
            "score": 3.1,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00366,
            "epssPercentile": 0.29676,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-19168",
            "title": "Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page",
            "summary": "Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00538,
            "epssPercentile": 0.43392,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-19169",
            "title": "Insufficient validation of untrusted input in Contextual Tasks in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to perform privilege escalation via a crafted HTML page",
            "summary": "Insufficient validation of untrusted input in Contextual Tasks in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: High)",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00358,
            "epssPercentile": 0.28827,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-19170",
            "title": "Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page",
            "summary": "Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
            "score": 9.6,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00384,
            "epssPercentile": 0.31545,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-19171",
            "title": "Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page",
            "summary": "Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
            "score": 9.6,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00372,
            "epssPercentile": 0.30379,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-19172",
            "title": "Google Chrome - Use After Free",
            "summary": "Use after free in Views in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
            "score": 8.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00347,
            "epssPercentile": 0.27701,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-19173",
            "title": "Google Chrome - Out-of-bounds Write",
            "summary": "Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
            "score": 8.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00324,
            "epssPercentile": 0.25019,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-19174",
            "title": "Integer overflow in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page",
            "summary": "Integer overflow in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00436,
            "epssPercentile": 0.36583,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-19175",
            "title": "Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page",
            "summary": "Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
            "score": 9.6,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00358,
            "epssPercentile": 0.28827,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-19176",
            "title": "Google Chrome - Use After Free",
            "summary": "Use after free in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00505,
            "epssPercentile": 0.41357,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-19177",
            "title": "Google Chrome - Improper Input Validation",
            "summary": "Insufficient validation of untrusted input in UI in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
            "score": 8.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00445,
            "epssPercentile": 0.37305,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70339",
            "title": "Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.",
            "score": 5.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00235,
            "epssPercentile": 0.14353,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.6,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-19175",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "The reviewed source does not require a restart.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-developer-tools-kb5120418",
      "slug": "microsoft-2026-08-developer-tools-kb5120418",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5120418",
      "title": "Deploy Microsoft Developer Tools security update KB5120418",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5120418",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016, plus 1 more",
      "platform": "Developer Tools",
      "release_version": "2.0.50727.8984 & 3.0.30729.8980 & 4.7.4144.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016, plus 1 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 3,
        "ids": [
          "CVE-2026-62872",
          "CVE-2026-65810",
          "CVE-2026-70354"
        ],
        "details": [
          {
            "id": "CVE-2026-62872",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00538,
            "epssPercentile": 0.43367,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65810",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00267,
            "epssPercentile": 0.18647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70354",
            "title": ".NET Core Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00294,
            "epssPercentile": 0.21675,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-62872",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-developer-tools-kb5120695",
      "slug": "microsoft-2026-08-developer-tools-kb5120695",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5120695",
      "title": "Deploy Microsoft Developer Tools security update KB5120695",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5120695",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft .NET Framework 3.5 on Windows Server 2012 R2, Microsoft .NET Framework 3.5 on Windows Server 2012 R2 (Server Core installation)",
      "platform": "Developer Tools",
      "release_version": "2.0.50727.8984 & 3.0.30729.8980",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft .NET Framework 3.5 on Windows Server 2012 R2, Microsoft .NET Framework 3.5 on Windows Server 2012 R2 (Server Core installation).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 3,
        "ids": [
          "CVE-2026-62872",
          "CVE-2026-65810",
          "CVE-2026-70354"
        ],
        "details": [
          {
            "id": "CVE-2026-62872",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00538,
            "epssPercentile": 0.43367,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65810",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00267,
            "epssPercentile": 0.18647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70354",
            "title": ".NET Core Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00294,
            "epssPercentile": 0.21675,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-62872",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-developer-tools-kb5120698",
      "slug": "microsoft-2026-08-developer-tools-kb5120698",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5120698",
      "title": "Deploy Microsoft Developer Tools security update KB5120698",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5120698",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for x64-based Systems, plus 2 more",
      "platform": "Developer Tools",
      "release_version": "2.0.50727.9070 & 3.0.30729.9068 & 4.7.4144.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 4 linked CVEs for Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for x64-based Systems, plus 2 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 4,
        "ids": [
          "CVE-2026-62872",
          "CVE-2026-62897",
          "CVE-2026-65810",
          "CVE-2026-70354"
        ],
        "details": [
          {
            "id": "CVE-2026-62872",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00538,
            "epssPercentile": 0.43367,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62897",
            "title": ".NET Framework Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00336,
            "epssPercentile": 0.26413,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65810",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00267,
            "epssPercentile": 0.18647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70354",
            "title": ".NET Core Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00294,
            "epssPercentile": 0.21675,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-62872",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-developer-tools-kb5120699",
      "slug": "microsoft-2026-08-developer-tools-kb5120699",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5120699",
      "title": "Deploy Microsoft Developer Tools security update KB5120699",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5120699",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 (Server Core installation)",
      "platform": "Developer Tools",
      "release_version": "4.7.4144.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 (Server Core installation).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 3,
        "ids": [
          "CVE-2026-62872",
          "CVE-2026-65810",
          "CVE-2026-70354"
        ],
        "details": [
          {
            "id": "CVE-2026-62872",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00538,
            "epssPercentile": 0.43367,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65810",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00267,
            "epssPercentile": 0.18647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70354",
            "title": ".NET Core Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00294,
            "epssPercentile": 0.21675,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-62872",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-developer-tools-kb5120700",
      "slug": "microsoft-2026-08-developer-tools-kb5120700",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5120700",
      "title": "Deploy Microsoft Developer Tools security update KB5120700",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5120700",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2 (Server Core installation)",
      "platform": "Developer Tools",
      "release_version": "4.7.4144.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2 (Server Core installation).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 3,
        "ids": [
          "CVE-2026-62872",
          "CVE-2026-65810",
          "CVE-2026-70354"
        ],
        "details": [
          {
            "id": "CVE-2026-62872",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00538,
            "epssPercentile": 0.43367,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65810",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00267,
            "epssPercentile": 0.18647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70354",
            "title": ".NET Core Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00294,
            "epssPercentile": 0.21675,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-62872",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-developer-tools-kb5120701",
      "slug": "microsoft-2026-08-developer-tools-kb5120701",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5120701",
      "title": "Deploy Microsoft Developer Tools security update KB5120701",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5120701",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for x64-based Systems, plus 3 more",
      "platform": "Developer Tools",
      "release_version": "2.0.50727.9183 & 3.0.30729.9169 & 4.8.4805.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for x64-based Systems, plus 3 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 3,
        "ids": [
          "CVE-2026-62872",
          "CVE-2026-65810",
          "CVE-2026-70354"
        ],
        "details": [
          {
            "id": "CVE-2026-62872",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00538,
            "epssPercentile": 0.43367,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65810",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00267,
            "epssPercentile": 0.18647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70354",
            "title": ".NET Core Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00294,
            "epssPercentile": 0.21675,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-62872",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-developer-tools-kb5120702",
      "slug": "microsoft-2026-08-developer-tools-kb5120702",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5120702",
      "title": "Deploy Microsoft Developer Tools security update KB5120702",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5120702",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 4.8 on Windows Server 2016, plus 1 more",
      "platform": "Developer Tools",
      "release_version": "4.8.4805.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 4.8 on Windows Server 2016, plus 1 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 3,
        "ids": [
          "CVE-2026-62872",
          "CVE-2026-65810",
          "CVE-2026-70354"
        ],
        "details": [
          {
            "id": "CVE-2026-62872",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00538,
            "epssPercentile": 0.43367,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65810",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00267,
            "epssPercentile": 0.18647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70354",
            "title": ".NET Core Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00294,
            "epssPercentile": 0.21675,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-62872",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-developer-tools-kb5120703",
      "slug": "microsoft-2026-08-developer-tools-kb5120703",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5120703",
      "title": "Deploy Microsoft Developer Tools security update KB5120703",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5120703",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for x64-based Systems, plus 2 more",
      "platform": "Developer Tools",
      "release_version": "2.0.50727.9070 & 3.0.30729.9068 & 4.8.4805.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 4 linked CVEs for Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for x64-based Systems, plus 2 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 4,
        "ids": [
          "CVE-2026-62872",
          "CVE-2026-62897",
          "CVE-2026-65810",
          "CVE-2026-70354"
        ],
        "details": [
          {
            "id": "CVE-2026-62872",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00538,
            "epssPercentile": 0.43367,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62897",
            "title": ".NET Framework Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00336,
            "epssPercentile": 0.26413,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65810",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00267,
            "epssPercentile": 0.18647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70354",
            "title": ".NET Core Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00294,
            "epssPercentile": 0.21675,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-62872",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-developer-tools-kb5120704",
      "slug": "microsoft-2026-08-developer-tools-kb5120704",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5120704",
      "title": "Deploy Microsoft Developer Tools security update KB5120704",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5120704",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft .NET Framework 4.8 on Windows Server 2012, Microsoft .NET Framework 4.8 on Windows Server 2012 (Server Core installation)",
      "platform": "Developer Tools",
      "release_version": "4.8.4805.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft .NET Framework 4.8 on Windows Server 2012, Microsoft .NET Framework 4.8 on Windows Server 2012 (Server Core installation).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 3,
        "ids": [
          "CVE-2026-62872",
          "CVE-2026-65810",
          "CVE-2026-70354"
        ],
        "details": [
          {
            "id": "CVE-2026-62872",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00538,
            "epssPercentile": 0.43367,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65810",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00267,
            "epssPercentile": 0.18647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70354",
            "title": ".NET Core Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00294,
            "epssPercentile": 0.21675,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-62872",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-developer-tools-kb5120705",
      "slug": "microsoft-2026-08-developer-tools-kb5120705",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5120705",
      "title": "Deploy Microsoft Developer Tools security update KB5120705",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5120705",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022, Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022 (Server Core installation)",
      "platform": "Developer Tools",
      "release_version": "2.0.50727.9183 & 3.0.30729.9169 & 4.8.4805.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022, Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022 (Server Core installation).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 3,
        "ids": [
          "CVE-2026-62872",
          "CVE-2026-65810",
          "CVE-2026-70354"
        ],
        "details": [
          {
            "id": "CVE-2026-62872",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00538,
            "epssPercentile": 0.43367,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65810",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00267,
            "epssPercentile": 0.18647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70354",
            "title": ".NET Core Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00294,
            "epssPercentile": 0.21675,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-62872",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-developer-tools-kb5120706",
      "slug": "microsoft-2026-08-developer-tools-kb5120706",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5120706",
      "title": "Deploy Microsoft Developer Tools security update KB5120706",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5120706",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft .NET Framework 4.8 on Windows Server 2012 R2, Microsoft .NET Framework 4.8 on Windows Server 2012 R2 (Server Core installation)",
      "platform": "Developer Tools",
      "release_version": "4.8.4805.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft .NET Framework 4.8 on Windows Server 2012 R2, Microsoft .NET Framework 4.8 on Windows Server 2012 R2 (Server Core installation).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 3,
        "ids": [
          "CVE-2026-62872",
          "CVE-2026-65810",
          "CVE-2026-70354"
        ],
        "details": [
          {
            "id": "CVE-2026-62872",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00538,
            "epssPercentile": 0.43367,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65810",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00267,
            "epssPercentile": 0.18647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70354",
            "title": ".NET Core Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00294,
            "epssPercentile": 0.21675,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-62872",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-developer-tools-kb5120708",
      "slug": "microsoft-2026-08-developer-tools-kb5120708",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5120708",
      "title": "Deploy Microsoft Developer Tools security update KB5120708",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5120708",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 25H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 25H2 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2025, plus 1 more",
      "platform": "Developer Tools",
      "release_version": "2.0.50727.9183 & 3.0.30729.9169 & 4.8.9344.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 25H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 25H2 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2025, plus 1 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 3,
        "ids": [
          "CVE-2026-62872",
          "CVE-2026-65810",
          "CVE-2026-70354"
        ],
        "details": [
          {
            "id": "CVE-2026-62872",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00538,
            "epssPercentile": 0.43367,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65810",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00267,
            "epssPercentile": 0.18647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70354",
            "title": ".NET Core Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00294,
            "epssPercentile": 0.21675,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-62872",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-developer-tools-kb5120709",
      "slug": "microsoft-2026-08-developer-tools-kb5120709",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5120709",
      "title": "Deploy Microsoft Developer Tools security update KB5120709",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5120709",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for x64-based Systems, plus 3 more",
      "platform": "Developer Tools",
      "release_version": "2.0.50727.9183 & 3.0.30729.9169 & 4.8.9343.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for x64-based Systems, plus 3 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 3,
        "ids": [
          "CVE-2026-62872",
          "CVE-2026-65810",
          "CVE-2026-70354"
        ],
        "details": [
          {
            "id": "CVE-2026-62872",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00538,
            "epssPercentile": 0.43367,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65810",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00267,
            "epssPercentile": 0.18647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70354",
            "title": ".NET Core Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00294,
            "epssPercentile": 0.21675,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-62872",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-developer-tools-kb5120710",
      "slug": "microsoft-2026-08-developer-tools-kb5120710",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5120710",
      "title": "Deploy Microsoft Developer Tools security update KB5120710",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5120710",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 24H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 24H2 for x64-based Systems",
      "platform": "Developer Tools",
      "release_version": "2.0.50727.9183 & 3.0.30729.9169 & 4.8.9343.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 24H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 24H2 for x64-based Systems.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 3,
        "ids": [
          "CVE-2026-62872",
          "CVE-2026-65810",
          "CVE-2026-70354"
        ],
        "details": [
          {
            "id": "CVE-2026-62872",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00538,
            "epssPercentile": 0.43367,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65810",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00267,
            "epssPercentile": 0.18647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70354",
            "title": ".NET Core Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00294,
            "epssPercentile": 0.21675,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-62872",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-developer-tools-kb5120711",
      "slug": "microsoft-2026-08-developer-tools-kb5120711",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5120711",
      "title": "Deploy Microsoft Developer Tools security update KB5120711",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5120711",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft .NET Framework 4.8.1 on Windows 11 Version 26H1 for ARM64-based Systems, Microsoft .NET Framework 4.8.1 on Windows 11 version 26H1 for x64-based Systems",
      "platform": "Developer Tools",
      "release_version": "4.8.9344.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 4 linked CVEs for Microsoft .NET Framework 4.8.1 on Windows 11 Version 26H1 for ARM64-based Systems, Microsoft .NET Framework 4.8.1 on Windows 11 version 26H1 for x64-based Systems.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 4,
        "ids": [
          "CVE-2026-62872",
          "CVE-2026-62897",
          "CVE-2026-65810",
          "CVE-2026-70354"
        ],
        "details": [
          {
            "id": "CVE-2026-62872",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00538,
            "epssPercentile": 0.43367,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62897",
            "title": ".NET Framework Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00336,
            "epssPercentile": 0.26413,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65810",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00267,
            "epssPercentile": 0.18647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70354",
            "title": ".NET Core Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00294,
            "epssPercentile": 0.21675,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-62872",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-developer-tools-kb5120713",
      "slug": "microsoft-2026-08-developer-tools-kb5120713",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5120713",
      "title": "Deploy Microsoft Developer Tools security update KB5120713",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5120713",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 23H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 23H2 for x64-based Systems",
      "platform": "Developer Tools",
      "release_version": "2.0.50727.9183 & 3.0.30729.9169 & 4.8.9343.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 23H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 23H2 for x64-based Systems.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 3,
        "ids": [
          "CVE-2026-62872",
          "CVE-2026-65810",
          "CVE-2026-70354"
        ],
        "details": [
          {
            "id": "CVE-2026-62872",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00538,
            "epssPercentile": 0.43367,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65810",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00267,
            "epssPercentile": 0.18647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70354",
            "title": ".NET Core Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00294,
            "epssPercentile": 0.21675,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-62872",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-developer-tools-kb5120714",
      "slug": "microsoft-2026-08-developer-tools-kb5120714",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5120714",
      "title": "Deploy Microsoft Developer Tools security update KB5120714",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5120714",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2022, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2022 (Server Core installation)",
      "platform": "Developer Tools",
      "release_version": "2.0.50727.9183 & 3.0.30729.9169 & 4.8.9343.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2022, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2022 (Server Core installation).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 3,
        "ids": [
          "CVE-2026-62872",
          "CVE-2026-65810",
          "CVE-2026-70354"
        ],
        "details": [
          {
            "id": "CVE-2026-62872",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00538,
            "epssPercentile": 0.43367,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65810",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00267,
            "epssPercentile": 0.18647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70354",
            "title": ".NET Core Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00294,
            "epssPercentile": 0.21675,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-62872",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-developer-tools-kb5120716",
      "slug": "microsoft-2026-08-developer-tools-kb5120716",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5120716",
      "title": "Deploy Microsoft Developer Tools security update KB5120716",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5120716",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft .NET Framework 3.5 on Windows Server 2012, Microsoft .NET Framework 3.5 on Windows Server 2012 (Server Core installation)",
      "platform": "Developer Tools",
      "release_version": "2.0.50727.8984 & 3.0.30729.8980",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft .NET Framework 3.5 on Windows Server 2012, Microsoft .NET Framework 3.5 on Windows Server 2012 (Server Core installation).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 3,
        "ids": [
          "CVE-2026-62872",
          "CVE-2026-65810",
          "CVE-2026-70354"
        ],
        "details": [
          {
            "id": "CVE-2026-62872",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00538,
            "epssPercentile": 0.43367,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65810",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00267,
            "epssPercentile": 0.18647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70354",
            "title": ".NET Core Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00294,
            "epssPercentile": 0.21675,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-62872",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-developer-tools-kb5120747",
      "slug": "microsoft-2026-08-developer-tools-kb5120747",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5120747",
      "title": "Deploy Microsoft Developer Tools security update KB5120747",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5120747",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft .NET Framework 3.5 on Windows 11 Version 26H1 for ARM64-based Systems, Microsoft .NET Framework 3.5 on Windows 11 version 26H1 for x64-based Systems",
      "platform": "Developer Tools",
      "release_version": "2.0.50727.9183 & 3.0.30729.9169",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 4 linked CVEs for Microsoft .NET Framework 3.5 on Windows 11 Version 26H1 for ARM64-based Systems, Microsoft .NET Framework 3.5 on Windows 11 version 26H1 for x64-based Systems.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 4,
        "ids": [
          "CVE-2026-62872",
          "CVE-2026-62897",
          "CVE-2026-65810",
          "CVE-2026-70354"
        ],
        "details": [
          {
            "id": "CVE-2026-62872",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00538,
            "epssPercentile": 0.43367,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62897",
            "title": ".NET Framework Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00336,
            "epssPercentile": 0.26413,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65810",
            "title": ".NET Framework Elevation of Privilege Vulnerability",
            "summary": "Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00267,
            "epssPercentile": 0.18647,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70354",
            "title": ".NET Core Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00294,
            "epssPercentile": 0.21675,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-62872",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-developer-tools-kb5122104",
      "slug": "microsoft-2026-08-developer-tools-kb5122104",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5122104",
      "title": "Deploy Microsoft Developer Tools security update KB5122104",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5122104",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": ".NET 8.0 installed on Linux, .NET 8.0 installed on Mac OS, .NET 8.0 installed on Windows",
      "platform": "Developer Tools",
      "release_version": "8.0.30",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 11 linked CVEs for .NET 8.0 installed on Linux, .NET 8.0 installed on Mac OS, .NET 8.0 installed on Windows.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 11,
        "ids": [
          "CVE-2026-58641",
          "CVE-2026-62871",
          "CVE-2026-62886",
          "CVE-2026-62897",
          "CVE-2026-62898",
          "CVE-2026-62899",
          "CVE-2026-62900",
          "CVE-2026-62901",
          "CVE-2026-62902",
          "CVE-2026-62909",
          "CVE-2026-70354"
        ],
        "details": [
          {
            "id": "CVE-2026-58641",
            "title": ".NET Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33696,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62871",
            "title": ".NET Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00396,
            "epssPercentile": 0.32875,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62886",
            "title": ".NET Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.3376,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62897",
            "title": ".NET Framework Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00336,
            "epssPercentile": 0.26413,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62898",
            "title": "Microsoft QUIC Information Disclosure Vulnerability",
            "summary": "Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01112,
            "epssPercentile": 0.63798,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62899",
            "title": ".NET Security Feature Bypass Vulnerability",
            "summary": "Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00706,
            "epssPercentile": 0.51057,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62900",
            "title": ".NET Information Disclosure Vulnerability",
            "summary": "Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00546,
            "epssPercentile": 0.43841,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62901",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01057,
            "epssPercentile": 0.62248,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62902",
            "title": ".NET Information Disclosure Vulnerability",
            "summary": "Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00778,
            "epssPercentile": 0.53546,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62909",
            "title": ".NET Elevation of Privilege Vulnerability",
            "summary": "Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00288,
            "epssPercentile": 0.21033,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70354",
            "title": ".NET Core Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00294,
            "epssPercentile": 0.21675,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-70354",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-developer-tools-kb5122105",
      "slug": "microsoft-2026-08-developer-tools-kb5122105",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5122105",
      "title": "Deploy Microsoft Developer Tools security update KB5122105",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5122105",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": ".NET 9.0 installed on Linux, .NET 9.0 installed on Mac OS, .NET 9.0 installed on Windows",
      "platform": "Developer Tools",
      "release_version": "9.0.19",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 11 linked CVEs for .NET 9.0 installed on Linux, .NET 9.0 installed on Mac OS, .NET 9.0 installed on Windows.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 11,
        "ids": [
          "CVE-2026-58641",
          "CVE-2026-62871",
          "CVE-2026-62886",
          "CVE-2026-62897",
          "CVE-2026-62898",
          "CVE-2026-62899",
          "CVE-2026-62900",
          "CVE-2026-62901",
          "CVE-2026-62902",
          "CVE-2026-62909",
          "CVE-2026-70354"
        ],
        "details": [
          {
            "id": "CVE-2026-58641",
            "title": ".NET Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33696,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62871",
            "title": ".NET Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00396,
            "epssPercentile": 0.32875,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62886",
            "title": ".NET Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.3376,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62897",
            "title": ".NET Framework Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00336,
            "epssPercentile": 0.26413,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62898",
            "title": "Microsoft QUIC Information Disclosure Vulnerability",
            "summary": "Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01112,
            "epssPercentile": 0.63798,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62899",
            "title": ".NET Security Feature Bypass Vulnerability",
            "summary": "Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00706,
            "epssPercentile": 0.51057,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62900",
            "title": ".NET Information Disclosure Vulnerability",
            "summary": "Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00546,
            "epssPercentile": 0.43841,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62901",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01057,
            "epssPercentile": 0.62248,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62902",
            "title": ".NET Information Disclosure Vulnerability",
            "summary": "Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00778,
            "epssPercentile": 0.53546,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62909",
            "title": ".NET Elevation of Privilege Vulnerability",
            "summary": "Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00288,
            "epssPercentile": 0.21033,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70354",
            "title": ".NET Core Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00294,
            "epssPercentile": 0.21675,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-70354",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-developer-tools-kb5122106",
      "slug": "microsoft-2026-08-developer-tools-kb5122106",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5122106",
      "title": "Deploy Microsoft Developer Tools security update KB5122106",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5122106",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": ".NET 10.0 installed on Linux, .NET 10.0 installed on Mac OS, .NET 10.0 installed on Windows",
      "platform": "Developer Tools",
      "release_version": "10.0.11",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 9 linked CVEs for .NET 10.0 installed on Linux, .NET 10.0 installed on Mac OS, .NET 10.0 installed on Windows.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 9,
        "ids": [
          "CVE-2026-58641",
          "CVE-2026-62886",
          "CVE-2026-62897",
          "CVE-2026-62898",
          "CVE-2026-62899",
          "CVE-2026-62900",
          "CVE-2026-62901",
          "CVE-2026-62909",
          "CVE-2026-70354"
        ],
        "details": [
          {
            "id": "CVE-2026-58641",
            "title": ".NET Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33696,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62886",
            "title": ".NET Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.3376,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62897",
            "title": ".NET Framework Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00336,
            "epssPercentile": 0.26413,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62898",
            "title": "Microsoft QUIC Information Disclosure Vulnerability",
            "summary": "Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01112,
            "epssPercentile": 0.63798,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62899",
            "title": ".NET Security Feature Bypass Vulnerability",
            "summary": "Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00706,
            "epssPercentile": 0.51057,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62900",
            "title": ".NET Information Disclosure Vulnerability",
            "summary": "Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00546,
            "epssPercentile": 0.43841,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62901",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01057,
            "epssPercentile": 0.62248,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62909",
            "title": ".NET Elevation of Privilege Vulnerability",
            "summary": "Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00288,
            "epssPercentile": 0.21033,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70354",
            "title": ".NET Core Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00294,
            "epssPercentile": 0.21675,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-70354",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-developer-tools-msrc-2026-08-developer-tools-17-14-38-microsoft-visual-studio-2022-version-17-14",
      "slug": "microsoft-2026-08-developer-tools-msrc-2026-08-developer-tools-17-14-38-microsoft-visual-studio-2022-version-17-14",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-08-developer-tools-17-14-38",
      "title": "Deploy Microsoft Developer Tools update for Microsoft Visual Studio 2022 version 17.14",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://msrc.microsoft.com/update-guide/releaseNote/2026-Aug",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft Visual Studio 2022 version 17.14",
      "platform": "Developer Tools",
      "release_version": "17.14.38",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 10 linked CVEs for Microsoft Visual Studio 2022 version 17.14.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 10,
        "ids": [
          "CVE-2026-62871",
          "CVE-2026-62886",
          "CVE-2026-62897",
          "CVE-2026-62898",
          "CVE-2026-62899",
          "CVE-2026-62900",
          "CVE-2026-62901",
          "CVE-2026-62902",
          "CVE-2026-62909",
          "CVE-2026-70354"
        ],
        "details": [
          {
            "id": "CVE-2026-62871",
            "title": ".NET Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00396,
            "epssPercentile": 0.32875,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62886",
            "title": ".NET Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.3376,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62897",
            "title": ".NET Framework Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00336,
            "epssPercentile": 0.26413,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62898",
            "title": "Microsoft QUIC Information Disclosure Vulnerability",
            "summary": "Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01112,
            "epssPercentile": 0.63798,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62899",
            "title": ".NET Security Feature Bypass Vulnerability",
            "summary": "Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00706,
            "epssPercentile": 0.51057,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62900",
            "title": ".NET Information Disclosure Vulnerability",
            "summary": "Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00546,
            "epssPercentile": 0.43841,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62901",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01057,
            "epssPercentile": 0.62248,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62902",
            "title": ".NET Information Disclosure Vulnerability",
            "summary": "Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00778,
            "epssPercentile": 0.53546,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62909",
            "title": ".NET Elevation of Privilege Vulnerability",
            "summary": "Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00288,
            "epssPercentile": 0.21033,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70354",
            "title": ".NET Core Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00294,
            "epssPercentile": 0.21675,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-70354",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-developer-tools-msrc-2026-08-developer-tools-18-8-3-microsoft-visual-studio-2026-version-18-8",
      "slug": "microsoft-2026-08-developer-tools-msrc-2026-08-developer-tools-18-8-3-microsoft-visual-studio-2026-version-18-8",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-08-developer-tools-18-8-3",
      "title": "Deploy Microsoft Developer Tools update for Microsoft Visual Studio 2026 version 18.8",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://msrc.microsoft.com/update-guide/releaseNote/2026-Aug",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft Visual Studio 2026 version 18.8",
      "platform": "Developer Tools",
      "release_version": "18.8.3",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 10 linked CVEs for Microsoft Visual Studio 2026 version 18.8.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 10,
        "ids": [
          "CVE-2026-62871",
          "CVE-2026-62886",
          "CVE-2026-62897",
          "CVE-2026-62898",
          "CVE-2026-62899",
          "CVE-2026-62900",
          "CVE-2026-62901",
          "CVE-2026-62902",
          "CVE-2026-62909",
          "CVE-2026-70354"
        ],
        "details": [
          {
            "id": "CVE-2026-62871",
            "title": ".NET Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00396,
            "epssPercentile": 0.32875,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62886",
            "title": ".NET Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.3376,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62897",
            "title": ".NET Framework Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00336,
            "epssPercentile": 0.26413,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62898",
            "title": "Microsoft QUIC Information Disclosure Vulnerability",
            "summary": "Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01112,
            "epssPercentile": 0.63798,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62899",
            "title": ".NET Security Feature Bypass Vulnerability",
            "summary": "Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00706,
            "epssPercentile": 0.51057,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62900",
            "title": ".NET Information Disclosure Vulnerability",
            "summary": "Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00546,
            "epssPercentile": 0.43841,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62901",
            "title": ".NET Denial of Service Vulnerability",
            "summary": "Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01057,
            "epssPercentile": 0.62248,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62902",
            "title": ".NET Information Disclosure Vulnerability",
            "summary": "Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00778,
            "epssPercentile": 0.53546,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62909",
            "title": ".NET Elevation of Privilege Vulnerability",
            "summary": "Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00288,
            "epssPercentile": 0.21033,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70354",
            "title": ".NET Core Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00294,
            "epssPercentile": 0.21675,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-70354",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-developer-tools-msrc-2026-08-developer-tools-2026-3-1-python-extension-for-visual-studio-code",
      "slug": "microsoft-2026-08-developer-tools-msrc-2026-08-developer-tools-2026-3-1-python-extension-for-visual-studio-code",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-08-developer-tools-2026-3-1",
      "title": "Deploy Microsoft Developer Tools update for Python extension for Visual Studio Code",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://github.com/microsoft/pylance-release/releases/tag/2026.3.1",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Python extension for Visual Studio Code",
      "platform": "Developer Tools",
      "release_version": "2026.3.1",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Python extension for Visual Studio Code.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-54981"
        ],
        "details": [
          {
            "id": "CVE-2026-54981",
            "title": "Visual Studio Code Python Extension Security Feature Bypass Vulnerability",
            "summary": "Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a security feature locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00393,
            "epssPercentile": 0.32536,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-54981",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-developer-tools-msrc-2026-08-developer-tools-7-4-19-0-powershell-7-4",
      "slug": "microsoft-2026-08-developer-tools-msrc-2026-08-developer-tools-7-4-19-0-powershell-7-4",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-08-developer-tools-7-4-19-0",
      "title": "Deploy Microsoft Developer Tools update for PowerShell 7.4",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://github.com/PowerShell/PowerShell/releases/tag/v7.4.19",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "PowerShell 7.4",
      "platform": "Developer Tools",
      "release_version": "7.4.19.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 5 linked CVEs for PowerShell 7.4.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 5,
        "ids": [
          "CVE-2026-50523",
          "CVE-2026-58612",
          "CVE-2026-59119",
          "CVE-2026-70337",
          "CVE-2026-70338"
        ],
        "details": [
          {
            "id": "CVE-2026-50523",
            "title": "Microsoft PowerShell Remote Code Execution Vulnerability",
            "summary": "Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00216,
            "epssPercentile": 0.11955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58612",
            "title": "PowerShell Information Disclosure Vulnerability",
            "summary": "Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network.",
            "score": 7.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00808,
            "epssPercentile": 0.54503,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59119",
            "title": "PowerShell Elevation of Privilege Vulnerability",
            "summary": "Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00321,
            "epssPercentile": 0.24741,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70337",
            "title": "Microsoft PowerShell Remote Code Execution Vulnerability",
            "summary": "Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00796,
            "epssPercentile": 0.54108,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70338",
            "title": "Microsoft PowerShell Security Feature Bypass Vulnerability",
            "summary": "Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23505,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-70337",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-developer-tools-msrc-2026-08-developer-tools-7-5-10-0-powershell-7-5",
      "slug": "microsoft-2026-08-developer-tools-msrc-2026-08-developer-tools-7-5-10-0-powershell-7-5",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-08-developer-tools-7-5-10-0",
      "title": "Deploy Microsoft Developer Tools update for PowerShell 7.5",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://github.com/PowerShell/PowerShell/releases/tag/v7.5.10",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "PowerShell 7.5",
      "platform": "Developer Tools",
      "release_version": "7.5.10.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 5 linked CVEs for PowerShell 7.5.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 5,
        "ids": [
          "CVE-2026-50523",
          "CVE-2026-58612",
          "CVE-2026-59119",
          "CVE-2026-70337",
          "CVE-2026-70338"
        ],
        "details": [
          {
            "id": "CVE-2026-50523",
            "title": "Microsoft PowerShell Remote Code Execution Vulnerability",
            "summary": "Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00216,
            "epssPercentile": 0.11955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58612",
            "title": "PowerShell Information Disclosure Vulnerability",
            "summary": "Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network.",
            "score": 7.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00808,
            "epssPercentile": 0.54503,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59119",
            "title": "PowerShell Elevation of Privilege Vulnerability",
            "summary": "Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00321,
            "epssPercentile": 0.24741,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70337",
            "title": "Microsoft PowerShell Remote Code Execution Vulnerability",
            "summary": "Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00796,
            "epssPercentile": 0.54108,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70338",
            "title": "Microsoft PowerShell Security Feature Bypass Vulnerability",
            "summary": "Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23505,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-70337",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-developer-tools-msrc-2026-08-developer-tools-7-6-5-powershell-7-6",
      "slug": "microsoft-2026-08-developer-tools-msrc-2026-08-developer-tools-7-6-5-powershell-7-6",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-08-developer-tools-7-6-5",
      "title": "Deploy Microsoft Developer Tools update for PowerShell 7.6",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://github.com/PowerShell/PowerShell/releases/tag/v7.6.5",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "PowerShell 7.6",
      "platform": "Developer Tools",
      "release_version": "7.6.5",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 5 linked CVEs for PowerShell 7.6.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 5,
        "ids": [
          "CVE-2026-50523",
          "CVE-2026-58612",
          "CVE-2026-59119",
          "CVE-2026-70337",
          "CVE-2026-70338"
        ],
        "details": [
          {
            "id": "CVE-2026-50523",
            "title": "Microsoft PowerShell Remote Code Execution Vulnerability",
            "summary": "Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00216,
            "epssPercentile": 0.11955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58612",
            "title": "PowerShell Information Disclosure Vulnerability",
            "summary": "Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network.",
            "score": 7.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00808,
            "epssPercentile": 0.54503,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59119",
            "title": "PowerShell Elevation of Privilege Vulnerability",
            "summary": "Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00321,
            "epssPercentile": 0.24741,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70337",
            "title": "Microsoft PowerShell Remote Code Execution Vulnerability",
            "summary": "Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00796,
            "epssPercentile": 0.54108,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70338",
            "title": "Microsoft PowerShell Security Feature Bypass Vulnerability",
            "summary": "Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23505,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-70337",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-developer-tools-msrc-2026-08-developer-tools-release-notes-visual-studio-code",
      "slug": "microsoft-2026-08-developer-tools-msrc-2026-08-developer-tools-release-notes-visual-studio-code",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-08-developer-tools-release-notes",
      "title": "Deploy Microsoft Developer Tools update for Visual Studio Code",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://code.visualstudio.com/Download",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Visual Studio Code",
      "platform": "Developer Tools",
      "release_version": "1.132.1",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 8 linked CVEs for Visual Studio Code.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 8,
        "ids": [
          "CVE-2026-47285",
          "CVE-2026-58650",
          "CVE-2026-59113",
          "CVE-2026-69278",
          "CVE-2026-69306",
          "CVE-2026-69320",
          "CVE-2026-70335",
          "CVE-2026-70336"
        ],
        "details": [
          {
            "id": "CVE-2026-47285",
            "title": "Visual Studio Code Information Disclosure Vulnerability",
            "summary": "Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00869,
            "epssPercentile": 0.56428,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58650",
            "title": "Visual Studio Code Security Feature Bypass Vulnerability",
            "summary": "Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00296,
            "epssPercentile": 0.21847,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59113",
            "title": "Visual Studio Code Remote Code Execution Vulnerability",
            "summary": "Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00695,
            "epssPercentile": 0.50673,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-69278",
            "title": "Visual Studio Code Security Feature Bypass Vulnerability",
            "summary": "Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00296,
            "epssPercentile": 0.21847,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-69306",
            "title": "Visual Studio Code Security Feature Bypass Vulnerability",
            "summary": "Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 8.2,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00412,
            "epssPercentile": 0.34486,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-69320",
            "title": "Visual Studio Code Remote Code Execution Vulnerability",
            "summary": "Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00456,
            "epssPercentile": 0.38098,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70335",
            "title": "GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability",
            "summary": "Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00421,
            "epssPercentile": 0.35292,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70336",
            "title": "Visual Studio Code Remote Code Execution Vulnerability",
            "summary": "Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00607,
            "epssPercentile": 0.46867,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-70336",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-developer-tools-msrc-2026-08-developer-tools-release-notes-microsoft-visual-studio-code-copilot-chat-extension",
      "slug": "microsoft-2026-08-developer-tools-msrc-2026-08-developer-tools-release-notes-microsoft-visual-studio-code-copilot-chat-extension",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-08-developer-tools-release-notes",
      "title": "Deploy Microsoft Developer Tools update for Microsoft Visual Studio Code CoPilot Chat Extension",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://code.visualstudio.com/Download",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft Visual Studio Code CoPilot Chat Extension",
      "platform": "Developer Tools",
      "release_version": "1.132.1",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Visual Studio Code CoPilot Chat Extension.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-65675"
        ],
        "details": [
          {
            "id": "CVE-2026-65675",
            "title": "CoPilot Chat Security Feature Bypass Vulnerability",
            "summary": "No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00497,
            "epssPercentile": 0.40855,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-65675",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-esu-kb5120249",
      "slug": "microsoft-2026-08-esu-kb5120249",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5120249",
      "title": "Deploy Microsoft ESU security update KB5120249",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5120249",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Windows 10 Version 22H2 for 32-bit Systems, Windows 10 Version 22H2 for ARM64-based Systems, Windows 10 Version 22H2 for x64-based Systems",
      "platform": "ESU",
      "release_version": "10.0.19045.7663",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 161 linked CVEs for Windows 10 Version 22H2 for 32-bit Systems, Windows 10 Version 22H2 for ARM64-based Systems, Windows 10 Version 22H2 for x64-based Systems. Microsoft reports exploitation for CVE-2026-68820.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 161,
        "ids": [
          "CVE-2026-42976",
          "CVE-2026-49179",
          "CVE-2026-50472",
          "CVE-2026-54113",
          "CVE-2026-54984",
          "CVE-2026-56174",
          "CVE-2026-59122",
          "CVE-2026-59125",
          "CVE-2026-59126",
          "CVE-2026-59127",
          "CVE-2026-59128",
          "CVE-2026-59130",
          "CVE-2026-59131",
          "CVE-2026-59132",
          "CVE-2026-59134",
          "CVE-2026-59135",
          "CVE-2026-59136",
          "CVE-2026-59137",
          "CVE-2026-59138",
          "CVE-2026-61345",
          "CVE-2026-61346",
          "CVE-2026-61347",
          "CVE-2026-61348",
          "CVE-2026-61349",
          "CVE-2026-61350",
          "CVE-2026-61352",
          "CVE-2026-61353",
          "CVE-2026-61355",
          "CVE-2026-61356",
          "CVE-2026-61358",
          "CVE-2026-61360",
          "CVE-2026-61363",
          "CVE-2026-61364",
          "CVE-2026-61365",
          "CVE-2026-61366",
          "CVE-2026-61367",
          "CVE-2026-61368",
          "CVE-2026-61918",
          "CVE-2026-61921",
          "CVE-2026-61923",
          "CVE-2026-61924",
          "CVE-2026-61925",
          "CVE-2026-61926",
          "CVE-2026-61928",
          "CVE-2026-61930",
          "CVE-2026-61932",
          "CVE-2026-61936",
          "CVE-2026-61937",
          "CVE-2026-61939",
          "CVE-2026-62690",
          "CVE-2026-62692",
          "CVE-2026-62696",
          "CVE-2026-62698",
          "CVE-2026-62699",
          "CVE-2026-62700",
          "CVE-2026-62701",
          "CVE-2026-62702",
          "CVE-2026-62703",
          "CVE-2026-62707",
          "CVE-2026-62709",
          "CVE-2026-62710",
          "CVE-2026-62711",
          "CVE-2026-62712",
          "CVE-2026-62713",
          "CVE-2026-62717",
          "CVE-2026-62719",
          "CVE-2026-62721",
          "CVE-2026-62723",
          "CVE-2026-62724",
          "CVE-2026-62725",
          "CVE-2026-62726",
          "CVE-2026-62727",
          "CVE-2026-62728",
          "CVE-2026-62729",
          "CVE-2026-62730",
          "CVE-2026-62732",
          "CVE-2026-62733",
          "CVE-2026-62734",
          "CVE-2026-62735",
          "CVE-2026-62738",
          "CVE-2026-62739",
          "CVE-2026-62740",
          "CVE-2026-62741",
          "CVE-2026-62743",
          "CVE-2026-62746",
          "CVE-2026-62747",
          "CVE-2026-62748",
          "CVE-2026-62750",
          "CVE-2026-62751",
          "CVE-2026-62752",
          "CVE-2026-62753",
          "CVE-2026-62754",
          "CVE-2026-62755",
          "CVE-2026-62757",
          "CVE-2026-62758",
          "CVE-2026-62768",
          "CVE-2026-62769",
          "CVE-2026-62770",
          "CVE-2026-62771",
          "CVE-2026-62773",
          "CVE-2026-62774",
          "CVE-2026-62777",
          "CVE-2026-62781",
          "CVE-2026-62782",
          "CVE-2026-62783",
          "CVE-2026-62784",
          "CVE-2026-62785",
          "CVE-2026-62786",
          "CVE-2026-62790",
          "CVE-2026-62792",
          "CVE-2026-62793",
          "CVE-2026-62795",
          "CVE-2026-62796",
          "CVE-2026-62797",
          "CVE-2026-62800",
          "CVE-2026-62816",
          "CVE-2026-62817",
          "CVE-2026-62819",
          "CVE-2026-62822",
          "CVE-2026-62832",
          "CVE-2026-62876",
          "CVE-2026-62877",
          "CVE-2026-62880",
          "CVE-2026-62881",
          "CVE-2026-62883",
          "CVE-2026-62885",
          "CVE-2026-62887",
          "CVE-2026-62888",
          "CVE-2026-62889",
          "CVE-2026-62890",
          "CVE-2026-62892",
          "CVE-2026-62894",
          "CVE-2026-62908",
          "CVE-2026-65662",
          "CVE-2026-65671",
          "CVE-2026-65678",
          "CVE-2026-65773",
          "CVE-2026-65774",
          "CVE-2026-65775",
          "CVE-2026-65784",
          "CVE-2026-65786",
          "CVE-2026-65787",
          "CVE-2026-65790",
          "CVE-2026-65794",
          "CVE-2026-65795",
          "CVE-2026-65797",
          "CVE-2026-65798",
          "CVE-2026-65799",
          "CVE-2026-65814",
          "CVE-2026-66799",
          "CVE-2026-66804",
          "CVE-2026-6726",
          "CVE-2026-6727",
          "CVE-2026-68820",
          "CVE-2026-70304",
          "CVE-2026-70307",
          "CVE-2026-70330",
          "CVE-2026-70344",
          "CVE-2026-70345",
          "CVE-2026-70346",
          "CVE-2026-70347"
        ],
        "details": [
          {
            "id": "CVE-2026-42976",
            "title": "Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11772,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49179",
            "title": "Windows Active Directory Domain Services Remote Code Execution Vulnerability",
            "summary": "Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00831,
            "epssPercentile": 0.55217,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50472",
            "title": "Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54113",
            "title": "Remote Procedure Call Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01126,
            "epssPercentile": 0.64162,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54984",
            "title": "Windows Imaging Component Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.006,
            "epssPercentile": 0.46535,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56174",
            "title": "Windows Narrator Braille Elevation of Privilege Vulnerability",
            "summary": "Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00291,
            "epssPercentile": 0.21293,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59122",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59125",
            "title": "Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability",
            "summary": "Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59126",
            "title": "Windows Event Logging Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59127",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23557,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59128",
            "title": "Windows Encrypting File System (EFS) Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31953,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59130",
            "title": "AMD Zen Information Disclosure Vulnerability",
            "summary": "No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00337,
            "epssPercentile": 0.26512,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59131",
            "title": "AMD Zen Information Disclosure Vulnerability",
            "summary": "No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00284,
            "epssPercentile": 0.20673,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59132",
            "title": "Windows TCP/IP Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01686,
            "epssPercentile": 0.75496,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59134",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00624,
            "epssPercentile": 0.47693,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59135",
            "title": "Microsoft Windows Search Component Information Disclosure Vulnerability",
            "summary": "Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0032,
            "epssPercentile": 0.24552,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59136",
            "title": "Microsoft COM for Windows Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0037,
            "epssPercentile": 0.30138,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59137",
            "title": "Windows Event Logging Service Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31953,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59138",
            "title": "Microsoft Remote Registry Service Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01042,
            "epssPercentile": 0.61833,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61345",
            "title": "Microsoft Remote Registry Service Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01042,
            "epssPercentile": 0.61834,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61346",
            "title": "Windows Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61347",
            "title": "Windows Event Logging Service Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61348",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0159,
            "epssPercentile": 0.7403,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61349",
            "title": "Windows Work Folder Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00238,
            "epssPercentile": 0.14813,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61350",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00449,
            "epssPercentile": 0.3762,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61352",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00428,
            "epssPercentile": 0.35876,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61353",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61355",
            "title": "Windows Sensor Data Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23556,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61356",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61358",
            "title": "Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0368,
            "epssPercentile": 0.88942,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61360",
            "title": "Windows GDI Information Disclosure Vulnerability",
            "summary": "Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31956,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61363",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00625,
            "epssPercentile": 0.47727,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61364",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61365",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61366",
            "title": "Windows Network Connection Broker Elevation of Privilege Vulnerability",
            "summary": "Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61367",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61368",
            "title": "Windows Hyper-V Information Disclosure Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally.",
            "score": 5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00372,
            "epssPercentile": 0.30393,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61918",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00869,
            "epssPercentile": 0.56428,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61921",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00829,
            "epssPercentile": 0.55174,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61923",
            "title": "Windows Display Enhancement Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61924",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00829,
            "epssPercentile": 0.55173,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61925",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00381,
            "epssPercentile": 0.31232,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61926",
            "title": "Windows USB Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61928",
            "title": "Windows Hello Tampering Vulnerability",
            "summary": "Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0021,
            "epssPercentile": 0.11257,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61930",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02092,
            "epssPercentile": 0.80405,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61932",
            "title": "Windows DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.2356,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61936",
            "title": "Windows Defender Firewall Service Security Feature Bypass Vulnerability",
            "summary": "Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00282,
            "epssPercentile": 0.20397,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61937",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61939",
            "title": "Winlogon Elevation of Privilege Vulnerability",
            "summary": "Use after free in Winlogon allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15759,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62690",
            "title": "Windows Push Notifications Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62692",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62696",
            "title": "Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03401,
            "epssPercentile": 0.88059,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62698",
            "title": "Microsoft Digest Authentication Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00361,
            "epssPercentile": 0.29142,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62699",
            "title": "Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to execute code with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00409,
            "epssPercentile": 0.34136,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62700",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62701",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62702",
            "title": "Windows Graphics Kernel Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00943,
            "epssPercentile": 0.58737,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62703",
            "title": "Windows DWM Core Library Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31954,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62707",
            "title": "Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62709",
            "title": "Windows GDI+ Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31908,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62710",
            "title": "Windows Device Association Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62711",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23518,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62712",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0038,
            "epssPercentile": 0.31158,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62713",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0195,
            "epssPercentile": 0.78893,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62717",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62719",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62721",
            "title": "Windows User-Mode Power Service (UMPS) Elevation of Privilege Vulnerability",
            "summary": "Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0038,
            "epssPercentile": 0.31198,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62723",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62724",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15758,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62725",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09788,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62726",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15758,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62727",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00186,
            "epssPercentile": 0.08256,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62728",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62729",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62730",
            "title": "Windows Wired AutoConfig Service Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62732",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62733",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62734",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62735",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00476,
            "epssPercentile": 0.39473,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62738",
            "title": "Windows Management Instrumentation Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62739",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00249,
            "epssPercentile": 0.1616,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62740",
            "title": "Windows Imaging Component Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31908,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62741",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02092,
            "epssPercentile": 0.80405,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62743",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31954,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62746",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31954,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62747",
            "title": "Windows Device Association Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23557,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62748",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08564,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62750",
            "title": "Windows HTTP Protocol Stack Tampering Vulnerability",
            "summary": "Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00574,
            "epssPercentile": 0.45288,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62751",
            "title": "Windows Projected File System Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23557,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62752",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23556,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62753",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00207,
            "epssPercentile": 0.10799,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62754",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62755",
            "title": "Windows DHCP Client Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62757",
            "title": "Windows Schannel Security Feature Bypass Vulnerability",
            "summary": "Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00255,
            "epssPercentile": 0.16929,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62758",
            "title": "Windows Remote Access Connection Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.14966,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62768",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62769",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62770",
            "title": "Windows Shell Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15007,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62771",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00249,
            "epssPercentile": 0.1616,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62773",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09787,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62774",
            "title": "Windows Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09787,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62777",
            "title": "Windows License Manager Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11773,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62781",
            "title": "RPC Runtime Library Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00519,
            "epssPercentile": 0.42242,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62782",
            "title": "Windows SMB Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00868,
            "epssPercentile": 0.56396,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62783",
            "title": "Windows Remote Access Connection Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01951,
            "epssPercentile": 0.78901,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62784",
            "title": "Microsoft Local Security Authority Server (lsasrv) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00934,
            "epssPercentile": 0.58442,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62785",
            "title": "Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00837,
            "epssPercentile": 0.55424,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62786",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62790",
            "title": "Windows SMBv3 Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00664,
            "epssPercentile": 0.49429,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62792",
            "title": "Windows TCP/IP Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00708,
            "epssPercentile": 0.51162,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62793",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23712,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62795",
            "title": "Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00607,
            "epssPercentile": 0.46873,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62796",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62797",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00334,
            "epssPercentile": 0.26156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62800",
            "title": "Windows SMBv3 Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00934,
            "epssPercentile": 0.58442,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62816",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00393,
            "epssPercentile": 0.32547,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62817",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00668,
            "epssPercentile": 0.49598,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62819",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00579,
            "epssPercentile": 0.45525,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62822",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00633,
            "epssPercentile": 0.48082,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62832",
            "title": "Windows User Profile Service Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03295,
            "epssPercentile": 0.87687,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62876",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62877",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62880",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15004,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62881",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62883",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17628,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62885",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62887",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22166,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62888",
            "title": "Windows DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01951,
            "epssPercentile": 0.78901,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62889",
            "title": "Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability",
            "summary": "Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0056,
            "epssPercentile": 0.44552,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62890",
            "title": "Windows GDI+ Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00269,
            "epssPercentile": 0.18868,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62892",
            "title": "Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability",
            "summary": "Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09787,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62894",
            "title": "Windows DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00249,
            "epssPercentile": 0.16159,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62908",
            "title": "Windows Backup Engine Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00153,
            "epssPercentile": 0.04738,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65662",
            "title": "Windows GDI Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65671",
            "title": "Remote Access API Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00257,
            "epssPercentile": 0.17266,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65678",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11662,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65773",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00242,
            "epssPercentile": 0.15314,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65774",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00257,
            "epssPercentile": 0.17266,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65775",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02609,
            "epssPercentile": 0.84381,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65784",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00299,
            "epssPercentile": 0.22201,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65786",
            "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65787",
            "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.2356,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65790",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15007,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65794",
            "title": "Windows SMB Client Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00651,
            "epssPercentile": 0.48924,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65795",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17627,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65797",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17582,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65798",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17628,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65799",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00253,
            "epssPercentile": 0.16631,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65814",
            "title": "Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00252,
            "epssPercentile": 0.16578,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66799",
            "title": "Windows Key Guard Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00269,
            "epssPercentile": 0.18868,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66804",
            "title": "Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.05309,
            "epssPercentile": 0.92057,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-6726",
            "title": "An information leakage vulnerability in the TCG TPM 2.0 reference code.",
            "summary": "An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key. See also TCG VRT0010.",
            "score": 7.9,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00215,
            "epssPercentile": 0.11783,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-6727",
            "title": "CVE-2026-6727",
            "summary": "A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with access to the TPM command interface may be able to exploit timing differences to recover information that could allow decryption of ciphertexts encrypted to TPM-managed RSA keys, including the RSA Endorsement Key (EK), including import blobs, credential blobs, and session salts. Under certain conditi",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00203,
            "epssPercentile": 0.10248,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68820",
            "title": "Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability",
            "summary": "Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2026-08-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.06184,
            "epssPercentile": 0.93023,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2026-08-25 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70304",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00316,
            "epssPercentile": 0.24068,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70307",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00322,
            "epssPercentile": 0.24811,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70330",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00316,
            "epssPercentile": 0.24068,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70344",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70345",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70346",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70347",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23517,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Exploitation reported by the vendor source",
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-62822",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-esu-kb5120385",
      "slug": "microsoft-2026-08-esu-kb5120385",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5120385",
      "title": "Deploy Microsoft ESU security update KB5120385",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5120385",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)",
      "platform": "ESU",
      "release_version": "6.3.9600.23338",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 144 linked CVEs for Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation). Microsoft reports exploitation for CVE-2026-68820.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 144,
        "ids": [
          "CVE-2026-42976",
          "CVE-2026-49179",
          "CVE-2026-50472",
          "CVE-2026-54984",
          "CVE-2026-59122",
          "CVE-2026-59127",
          "CVE-2026-59128",
          "CVE-2026-59130",
          "CVE-2026-59131",
          "CVE-2026-59132",
          "CVE-2026-59134",
          "CVE-2026-59135",
          "CVE-2026-59136",
          "CVE-2026-59137",
          "CVE-2026-59138",
          "CVE-2026-61345",
          "CVE-2026-61347",
          "CVE-2026-61348",
          "CVE-2026-61349",
          "CVE-2026-61350",
          "CVE-2026-61352",
          "CVE-2026-61353",
          "CVE-2026-61360",
          "CVE-2026-61363",
          "CVE-2026-61364",
          "CVE-2026-61365",
          "CVE-2026-61366",
          "CVE-2026-61367",
          "CVE-2026-61918",
          "CVE-2026-61920",
          "CVE-2026-61921",
          "CVE-2026-61924",
          "CVE-2026-61925",
          "CVE-2026-61926",
          "CVE-2026-61937",
          "CVE-2026-61939",
          "CVE-2026-62692",
          "CVE-2026-62698",
          "CVE-2026-62699",
          "CVE-2026-62700",
          "CVE-2026-62701",
          "CVE-2026-62709",
          "CVE-2026-62711",
          "CVE-2026-62712",
          "CVE-2026-62714",
          "CVE-2026-62715",
          "CVE-2026-62716",
          "CVE-2026-62717",
          "CVE-2026-62718",
          "CVE-2026-62719",
          "CVE-2026-62720",
          "CVE-2026-62721",
          "CVE-2026-62723",
          "CVE-2026-62724",
          "CVE-2026-62725",
          "CVE-2026-62726",
          "CVE-2026-62727",
          "CVE-2026-62728",
          "CVE-2026-62729",
          "CVE-2026-62730",
          "CVE-2026-62732",
          "CVE-2026-62733",
          "CVE-2026-62734",
          "CVE-2026-62735",
          "CVE-2026-62738",
          "CVE-2026-62740",
          "CVE-2026-62741",
          "CVE-2026-62742",
          "CVE-2026-62743",
          "CVE-2026-62745",
          "CVE-2026-62746",
          "CVE-2026-62748",
          "CVE-2026-62750",
          "CVE-2026-62752",
          "CVE-2026-62753",
          "CVE-2026-62754",
          "CVE-2026-62755",
          "CVE-2026-62757",
          "CVE-2026-62758",
          "CVE-2026-62761",
          "CVE-2026-62768",
          "CVE-2026-62769",
          "CVE-2026-62770",
          "CVE-2026-62773",
          "CVE-2026-62776",
          "CVE-2026-62778",
          "CVE-2026-62781",
          "CVE-2026-62784",
          "CVE-2026-62785",
          "CVE-2026-62786",
          "CVE-2026-62787",
          "CVE-2026-62790",
          "CVE-2026-62792",
          "CVE-2026-62793",
          "CVE-2026-62795",
          "CVE-2026-62796",
          "CVE-2026-62797",
          "CVE-2026-62800",
          "CVE-2026-62803",
          "CVE-2026-62807",
          "CVE-2026-62812",
          "CVE-2026-62814",
          "CVE-2026-62816",
          "CVE-2026-62818",
          "CVE-2026-62819",
          "CVE-2026-62822",
          "CVE-2026-62823",
          "CVE-2026-62824",
          "CVE-2026-62876",
          "CVE-2026-62877",
          "CVE-2026-62878",
          "CVE-2026-62880",
          "CVE-2026-62881",
          "CVE-2026-62883",
          "CVE-2026-62885",
          "CVE-2026-62887",
          "CVE-2026-62889",
          "CVE-2026-62890",
          "CVE-2026-62893",
          "CVE-2026-62908",
          "CVE-2026-65662",
          "CVE-2026-65671",
          "CVE-2026-65679",
          "CVE-2026-65774",
          "CVE-2026-65775",
          "CVE-2026-65784",
          "CVE-2026-65790",
          "CVE-2026-65791",
          "CVE-2026-65794",
          "CVE-2026-65796",
          "CVE-2026-65797",
          "CVE-2026-65798",
          "CVE-2026-65799",
          "CVE-2026-65814",
          "CVE-2026-66799",
          "CVE-2026-68819",
          "CVE-2026-68820",
          "CVE-2026-70304",
          "CVE-2026-70307",
          "CVE-2026-70330",
          "CVE-2026-70344",
          "CVE-2026-70345",
          "CVE-2026-70346",
          "CVE-2026-70347"
        ],
        "details": [
          {
            "id": "CVE-2026-42976",
            "title": "Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11772,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49179",
            "title": "Windows Active Directory Domain Services Remote Code Execution Vulnerability",
            "summary": "Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00831,
            "epssPercentile": 0.55217,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50472",
            "title": "Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54984",
            "title": "Windows Imaging Component Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.006,
            "epssPercentile": 0.46535,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59122",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59127",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23557,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59128",
            "title": "Windows Encrypting File System (EFS) Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31953,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59130",
            "title": "AMD Zen Information Disclosure Vulnerability",
            "summary": "No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00337,
            "epssPercentile": 0.26512,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59131",
            "title": "AMD Zen Information Disclosure Vulnerability",
            "summary": "No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00284,
            "epssPercentile": 0.20673,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59132",
            "title": "Windows TCP/IP Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01686,
            "epssPercentile": 0.75496,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59134",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00624,
            "epssPercentile": 0.47693,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59135",
            "title": "Microsoft Windows Search Component Information Disclosure Vulnerability",
            "summary": "Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0032,
            "epssPercentile": 0.24552,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59136",
            "title": "Microsoft COM for Windows Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0037,
            "epssPercentile": 0.30138,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59137",
            "title": "Windows Event Logging Service Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31953,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59138",
            "title": "Microsoft Remote Registry Service Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01042,
            "epssPercentile": 0.61833,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61345",
            "title": "Microsoft Remote Registry Service Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01042,
            "epssPercentile": 0.61834,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61347",
            "title": "Windows Event Logging Service Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61348",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0159,
            "epssPercentile": 0.7403,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61349",
            "title": "Windows Work Folder Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00238,
            "epssPercentile": 0.14813,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61350",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00449,
            "epssPercentile": 0.3762,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61352",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00428,
            "epssPercentile": 0.35876,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61353",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61360",
            "title": "Windows GDI Information Disclosure Vulnerability",
            "summary": "Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31956,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61363",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00625,
            "epssPercentile": 0.47727,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61364",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61365",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61366",
            "title": "Windows Network Connection Broker Elevation of Privilege Vulnerability",
            "summary": "Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61367",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61918",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00869,
            "epssPercentile": 0.56428,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61920",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a network.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00484,
            "epssPercentile": 0.39993,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61921",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00829,
            "epssPercentile": 0.55174,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61924",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00829,
            "epssPercentile": 0.55173,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61925",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00381,
            "epssPercentile": 0.31232,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61926",
            "title": "Windows USB Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61937",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61939",
            "title": "Winlogon Elevation of Privilege Vulnerability",
            "summary": "Use after free in Winlogon allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15759,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62692",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62698",
            "title": "Microsoft Digest Authentication Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00361,
            "epssPercentile": 0.29142,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62699",
            "title": "Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to execute code with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00409,
            "epssPercentile": 0.34136,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62700",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62701",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62709",
            "title": "Windows GDI+ Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31908,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62711",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23518,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62712",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0038,
            "epssPercentile": 0.31158,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62714",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00468,
            "epssPercentile": 0.3888,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62715",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0048,
            "epssPercentile": 0.3977,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62716",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00468,
            "epssPercentile": 0.3888,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62717",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62718",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0048,
            "epssPercentile": 0.39771,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62719",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62720",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00468,
            "epssPercentile": 0.3888,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62721",
            "title": "Windows User-Mode Power Service (UMPS) Elevation of Privilege Vulnerability",
            "summary": "Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0038,
            "epssPercentile": 0.31198,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62723",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62724",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15758,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62725",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09788,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62726",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15758,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62727",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00186,
            "epssPercentile": 0.08256,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62728",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62729",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62730",
            "title": "Windows Wired AutoConfig Service Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62732",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62733",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62734",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62735",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00476,
            "epssPercentile": 0.39473,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62738",
            "title": "Windows Management Instrumentation Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62740",
            "title": "Windows Imaging Component Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31908,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62741",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02092,
            "epssPercentile": 0.80405,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62742",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0048,
            "epssPercentile": 0.39771,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62743",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31954,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62745",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00361,
            "epssPercentile": 0.29156,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62746",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31954,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62748",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08564,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62750",
            "title": "Windows HTTP Protocol Stack Tampering Vulnerability",
            "summary": "Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00574,
            "epssPercentile": 0.45288,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62752",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23556,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62753",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00207,
            "epssPercentile": 0.10799,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62754",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62755",
            "title": "Windows DHCP Client Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62757",
            "title": "Windows Schannel Security Feature Bypass Vulnerability",
            "summary": "Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00255,
            "epssPercentile": 0.16929,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62758",
            "title": "Windows Remote Access Connection Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.14966,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62761",
            "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00355,
            "epssPercentile": 0.28559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62768",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62769",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62770",
            "title": "Windows Shell Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15007,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62773",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09787,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62776",
            "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00271,
            "epssPercentile": 0.19237,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62778",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00506,
            "epssPercentile": 0.41401,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62781",
            "title": "RPC Runtime Library Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00519,
            "epssPercentile": 0.42242,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62784",
            "title": "Microsoft Local Security Authority Server (lsasrv) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00934,
            "epssPercentile": 0.58442,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62785",
            "title": "Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00837,
            "epssPercentile": 0.55424,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62786",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62787",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows DNS allows an authorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0053,
            "epssPercentile": 0.4292,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62790",
            "title": "Windows SMBv3 Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00664,
            "epssPercentile": 0.49429,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62792",
            "title": "Windows TCP/IP Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00708,
            "epssPercentile": 0.51162,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62793",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23712,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62795",
            "title": "Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00607,
            "epssPercentile": 0.46873,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62796",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62797",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00334,
            "epssPercentile": 0.26156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62800",
            "title": "Windows SMBv3 Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00934,
            "epssPercentile": 0.58442,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62803",
            "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00371,
            "epssPercentile": 0.30191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62807",
            "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00371,
            "epssPercentile": 0.30191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62812",
            "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00291,
            "epssPercentile": 0.21362,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62814",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00537,
            "epssPercentile": 0.43342,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62816",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00393,
            "epssPercentile": 0.32547,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62818",
            "title": "Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability",
            "summary": "Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00972,
            "epssPercentile": 0.59701,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62819",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00579,
            "epssPercentile": 0.45525,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62822",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00633,
            "epssPercentile": 0.48082,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62823",
            "title": "Windows DHCP Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00662,
            "epssPercentile": 0.49371,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62824",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00625,
            "epssPercentile": 0.47758,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62876",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62877",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62878",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0126,
            "epssPercentile": 0.67668,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62880",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15004,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62881",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62883",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17628,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62885",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62887",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22166,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62889",
            "title": "Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability",
            "summary": "Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0056,
            "epssPercentile": 0.44552,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62890",
            "title": "Windows GDI+ Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00269,
            "epssPercentile": 0.18868,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62893",
            "title": "Windows Deployment Services TFTP Server Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02732,
            "epssPercentile": 0.85128,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62908",
            "title": "Windows Backup Engine Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00153,
            "epssPercentile": 0.04738,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65662",
            "title": "Windows GDI Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65671",
            "title": "Remote Access API Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00257,
            "epssPercentile": 0.17266,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65679",
            "title": "Windows iSCSI Target Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00566,
            "epssPercentile": 0.44906,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65774",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00257,
            "epssPercentile": 0.17266,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65775",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02609,
            "epssPercentile": 0.84381,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65784",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00299,
            "epssPercentile": 0.22201,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65790",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15007,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65791",
            "title": "Windows iSCSI Target Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.006,
            "epssPercentile": 0.46555,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65794",
            "title": "Windows SMB Client Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00651,
            "epssPercentile": 0.48924,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65796",
            "title": "Windows iSCSI Target Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00528,
            "epssPercentile": 0.42787,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65797",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17582,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65798",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17628,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65799",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00253,
            "epssPercentile": 0.16631,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65814",
            "title": "Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00252,
            "epssPercentile": 0.16578,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66799",
            "title": "Windows Key Guard Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00269,
            "epssPercentile": 0.18868,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68819",
            "title": "Windows Network File System Denial of Service Vulnerability",
            "summary": "Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00684,
            "epssPercentile": 0.50268,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68820",
            "title": "Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability",
            "summary": "Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2026-08-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.06184,
            "epssPercentile": 0.93023,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2026-08-25 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70304",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00316,
            "epssPercentile": 0.24068,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70307",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00322,
            "epssPercentile": 0.24811,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70330",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00316,
            "epssPercentile": 0.24068,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70344",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70345",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70346",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70347",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23517,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Exploitation reported by the vendor source",
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-65791",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-esu-kb5120386",
      "slug": "microsoft-2026-08-esu-kb5120386",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5120386",
      "title": "Deploy Microsoft ESU security update KB5120386",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5120386",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Windows Server 2012, Windows Server 2012 (Server Core installation)",
      "platform": "ESU",
      "release_version": "6.2.9200.26280",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 139 linked CVEs for Windows Server 2012, Windows Server 2012 (Server Core installation). Microsoft reports exploitation for CVE-2026-68820.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 139,
        "ids": [
          "CVE-2026-42976",
          "CVE-2026-49179",
          "CVE-2026-50472",
          "CVE-2026-54113",
          "CVE-2026-54984",
          "CVE-2026-59122",
          "CVE-2026-59127",
          "CVE-2026-59128",
          "CVE-2026-59132",
          "CVE-2026-59134",
          "CVE-2026-59135",
          "CVE-2026-59136",
          "CVE-2026-59137",
          "CVE-2026-59138",
          "CVE-2026-61345",
          "CVE-2026-61347",
          "CVE-2026-61348",
          "CVE-2026-61350",
          "CVE-2026-61352",
          "CVE-2026-61353",
          "CVE-2026-61360",
          "CVE-2026-61363",
          "CVE-2026-61364",
          "CVE-2026-61365",
          "CVE-2026-61366",
          "CVE-2026-61367",
          "CVE-2026-61918",
          "CVE-2026-61921",
          "CVE-2026-61924",
          "CVE-2026-61925",
          "CVE-2026-61926",
          "CVE-2026-61937",
          "CVE-2026-61939",
          "CVE-2026-62692",
          "CVE-2026-62698",
          "CVE-2026-62699",
          "CVE-2026-62700",
          "CVE-2026-62701",
          "CVE-2026-62709",
          "CVE-2026-62711",
          "CVE-2026-62712",
          "CVE-2026-62714",
          "CVE-2026-62716",
          "CVE-2026-62717",
          "CVE-2026-62718",
          "CVE-2026-62719",
          "CVE-2026-62720",
          "CVE-2026-62721",
          "CVE-2026-62723",
          "CVE-2026-62724",
          "CVE-2026-62725",
          "CVE-2026-62726",
          "CVE-2026-62727",
          "CVE-2026-62728",
          "CVE-2026-62729",
          "CVE-2026-62730",
          "CVE-2026-62732",
          "CVE-2026-62733",
          "CVE-2026-62734",
          "CVE-2026-62735",
          "CVE-2026-62738",
          "CVE-2026-62740",
          "CVE-2026-62741",
          "CVE-2026-62742",
          "CVE-2026-62743",
          "CVE-2026-62745",
          "CVE-2026-62746",
          "CVE-2026-62748",
          "CVE-2026-62750",
          "CVE-2026-62752",
          "CVE-2026-62753",
          "CVE-2026-62754",
          "CVE-2026-62755",
          "CVE-2026-62757",
          "CVE-2026-62758",
          "CVE-2026-62761",
          "CVE-2026-62768",
          "CVE-2026-62769",
          "CVE-2026-62770",
          "CVE-2026-62773",
          "CVE-2026-62776",
          "CVE-2026-62778",
          "CVE-2026-62781",
          "CVE-2026-62784",
          "CVE-2026-62785",
          "CVE-2026-62786",
          "CVE-2026-62787",
          "CVE-2026-62790",
          "CVE-2026-62792",
          "CVE-2026-62793",
          "CVE-2026-62795",
          "CVE-2026-62796",
          "CVE-2026-62797",
          "CVE-2026-62800",
          "CVE-2026-62803",
          "CVE-2026-62807",
          "CVE-2026-62812",
          "CVE-2026-62814",
          "CVE-2026-62816",
          "CVE-2026-62818",
          "CVE-2026-62819",
          "CVE-2026-62822",
          "CVE-2026-62823",
          "CVE-2026-62824",
          "CVE-2026-62876",
          "CVE-2026-62877",
          "CVE-2026-62878",
          "CVE-2026-62880",
          "CVE-2026-62881",
          "CVE-2026-62883",
          "CVE-2026-62885",
          "CVE-2026-62887",
          "CVE-2026-62889",
          "CVE-2026-62890",
          "CVE-2026-62893",
          "CVE-2026-62908",
          "CVE-2026-65662",
          "CVE-2026-65679",
          "CVE-2026-65774",
          "CVE-2026-65775",
          "CVE-2026-65784",
          "CVE-2026-65790",
          "CVE-2026-65791",
          "CVE-2026-65794",
          "CVE-2026-65796",
          "CVE-2026-65797",
          "CVE-2026-65798",
          "CVE-2026-65799",
          "CVE-2026-65814",
          "CVE-2026-66799",
          "CVE-2026-68819",
          "CVE-2026-68820",
          "CVE-2026-70304",
          "CVE-2026-70307",
          "CVE-2026-70330",
          "CVE-2026-70344",
          "CVE-2026-70345",
          "CVE-2026-70346",
          "CVE-2026-70347"
        ],
        "details": [
          {
            "id": "CVE-2026-42976",
            "title": "Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11772,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49179",
            "title": "Windows Active Directory Domain Services Remote Code Execution Vulnerability",
            "summary": "Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00831,
            "epssPercentile": 0.55217,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50472",
            "title": "Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54113",
            "title": "Remote Procedure Call Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01126,
            "epssPercentile": 0.64162,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54984",
            "title": "Windows Imaging Component Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.006,
            "epssPercentile": 0.46535,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59122",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59127",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23557,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59128",
            "title": "Windows Encrypting File System (EFS) Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31953,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59132",
            "title": "Windows TCP/IP Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01686,
            "epssPercentile": 0.75496,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59134",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00624,
            "epssPercentile": 0.47693,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59135",
            "title": "Microsoft Windows Search Component Information Disclosure Vulnerability",
            "summary": "Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0032,
            "epssPercentile": 0.24552,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59136",
            "title": "Microsoft COM for Windows Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0037,
            "epssPercentile": 0.30138,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59137",
            "title": "Windows Event Logging Service Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31953,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59138",
            "title": "Microsoft Remote Registry Service Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01042,
            "epssPercentile": 0.61833,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61345",
            "title": "Microsoft Remote Registry Service Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01042,
            "epssPercentile": 0.61834,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61347",
            "title": "Windows Event Logging Service Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61348",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0159,
            "epssPercentile": 0.7403,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61350",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00449,
            "epssPercentile": 0.3762,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61352",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00428,
            "epssPercentile": 0.35876,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61353",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61360",
            "title": "Windows GDI Information Disclosure Vulnerability",
            "summary": "Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31956,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61363",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00625,
            "epssPercentile": 0.47727,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61364",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61365",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61366",
            "title": "Windows Network Connection Broker Elevation of Privilege Vulnerability",
            "summary": "Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61367",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61918",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00869,
            "epssPercentile": 0.56428,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61921",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00829,
            "epssPercentile": 0.55174,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61924",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00829,
            "epssPercentile": 0.55173,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61925",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00381,
            "epssPercentile": 0.31232,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61926",
            "title": "Windows USB Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61937",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61939",
            "title": "Winlogon Elevation of Privilege Vulnerability",
            "summary": "Use after free in Winlogon allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15759,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62692",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62698",
            "title": "Microsoft Digest Authentication Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00361,
            "epssPercentile": 0.29142,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62699",
            "title": "Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to execute code with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00409,
            "epssPercentile": 0.34136,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62700",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62701",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62709",
            "title": "Windows GDI+ Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31908,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62711",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23518,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62712",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0038,
            "epssPercentile": 0.31158,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62714",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00468,
            "epssPercentile": 0.3888,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62716",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00468,
            "epssPercentile": 0.3888,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62717",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62718",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0048,
            "epssPercentile": 0.39771,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62719",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62720",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00468,
            "epssPercentile": 0.3888,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62721",
            "title": "Windows User-Mode Power Service (UMPS) Elevation of Privilege Vulnerability",
            "summary": "Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0038,
            "epssPercentile": 0.31198,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62723",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62724",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15758,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62725",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09788,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62726",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15758,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62727",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00186,
            "epssPercentile": 0.08256,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62728",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62729",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62730",
            "title": "Windows Wired AutoConfig Service Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62732",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62733",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62734",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62735",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00476,
            "epssPercentile": 0.39473,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62738",
            "title": "Windows Management Instrumentation Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62740",
            "title": "Windows Imaging Component Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31908,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62741",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02092,
            "epssPercentile": 0.80405,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62742",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0048,
            "epssPercentile": 0.39771,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62743",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31954,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62745",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00361,
            "epssPercentile": 0.29156,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62746",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31954,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62748",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08564,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62750",
            "title": "Windows HTTP Protocol Stack Tampering Vulnerability",
            "summary": "Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00574,
            "epssPercentile": 0.45288,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62752",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23556,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62753",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00207,
            "epssPercentile": 0.10799,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62754",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62755",
            "title": "Windows DHCP Client Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62757",
            "title": "Windows Schannel Security Feature Bypass Vulnerability",
            "summary": "Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00255,
            "epssPercentile": 0.16929,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62758",
            "title": "Windows Remote Access Connection Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.14966,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62761",
            "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00355,
            "epssPercentile": 0.28559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62768",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62769",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62770",
            "title": "Windows Shell Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15007,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62773",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09787,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62776",
            "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00271,
            "epssPercentile": 0.19237,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62778",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00506,
            "epssPercentile": 0.41401,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62781",
            "title": "RPC Runtime Library Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00519,
            "epssPercentile": 0.42242,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62784",
            "title": "Microsoft Local Security Authority Server (lsasrv) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00934,
            "epssPercentile": 0.58442,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62785",
            "title": "Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00837,
            "epssPercentile": 0.55424,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62786",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62787",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows DNS allows an authorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0053,
            "epssPercentile": 0.4292,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62790",
            "title": "Windows SMBv3 Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00664,
            "epssPercentile": 0.49429,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62792",
            "title": "Windows TCP/IP Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00708,
            "epssPercentile": 0.51162,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62793",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23712,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62795",
            "title": "Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00607,
            "epssPercentile": 0.46873,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62796",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62797",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00334,
            "epssPercentile": 0.26156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62800",
            "title": "Windows SMBv3 Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00934,
            "epssPercentile": 0.58442,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62803",
            "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00371,
            "epssPercentile": 0.30191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62807",
            "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00371,
            "epssPercentile": 0.30191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62812",
            "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00291,
            "epssPercentile": 0.21362,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62814",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00537,
            "epssPercentile": 0.43342,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62816",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00393,
            "epssPercentile": 0.32547,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62818",
            "title": "Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability",
            "summary": "Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00972,
            "epssPercentile": 0.59701,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62819",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00579,
            "epssPercentile": 0.45525,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62822",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00633,
            "epssPercentile": 0.48082,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62823",
            "title": "Windows DHCP Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00662,
            "epssPercentile": 0.49371,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62824",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00625,
            "epssPercentile": 0.47758,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62876",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62877",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62878",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0126,
            "epssPercentile": 0.67668,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62880",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15004,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62881",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62883",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17628,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62885",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62887",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22166,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62889",
            "title": "Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability",
            "summary": "Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0056,
            "epssPercentile": 0.44552,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62890",
            "title": "Windows GDI+ Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00269,
            "epssPercentile": 0.18868,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62893",
            "title": "Windows Deployment Services TFTP Server Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02732,
            "epssPercentile": 0.85128,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62908",
            "title": "Windows Backup Engine Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00153,
            "epssPercentile": 0.04738,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65662",
            "title": "Windows GDI Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65679",
            "title": "Windows iSCSI Target Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00566,
            "epssPercentile": 0.44906,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65774",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00257,
            "epssPercentile": 0.17266,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65775",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02609,
            "epssPercentile": 0.84381,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65784",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00299,
            "epssPercentile": 0.22201,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65790",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15007,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65791",
            "title": "Windows iSCSI Target Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.006,
            "epssPercentile": 0.46555,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65794",
            "title": "Windows SMB Client Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00651,
            "epssPercentile": 0.48924,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65796",
            "title": "Windows iSCSI Target Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00528,
            "epssPercentile": 0.42787,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65797",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17582,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65798",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17628,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65799",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00253,
            "epssPercentile": 0.16631,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65814",
            "title": "Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00252,
            "epssPercentile": 0.16578,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66799",
            "title": "Windows Key Guard Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00269,
            "epssPercentile": 0.18868,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68819",
            "title": "Windows Network File System Denial of Service Vulnerability",
            "summary": "Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00684,
            "epssPercentile": 0.50268,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68820",
            "title": "Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability",
            "summary": "Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2026-08-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.06184,
            "epssPercentile": 0.93023,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2026-08-25 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70304",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00316,
            "epssPercentile": 0.24068,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70307",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00322,
            "epssPercentile": 0.24811,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70330",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00316,
            "epssPercentile": 0.24068,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70344",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70345",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70346",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70347",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23517,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Exploitation reported by the vendor source",
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-65791",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-esu-kb5121574",
      "slug": "microsoft-2026-08-esu-kb5121574",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5121574",
      "title": "Deploy Microsoft ESU security update KB5121574",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5121574",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft Exchange Server 2019 Cumulative Update 15",
      "platform": "ESU",
      "release_version": "15.02.1748.049",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 7 linked CVEs for Microsoft Exchange Server 2019 Cumulative Update 15.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 7,
        "ids": [
          "CVE-2026-62910",
          "CVE-2026-62911",
          "CVE-2026-62912",
          "CVE-2026-62913",
          "CVE-2026-62914",
          "CVE-2026-62915",
          "CVE-2026-65813"
        ],
        "details": [
          {
            "id": "CVE-2026-62910",
            "title": "Microsoft Exchange Server Elevation of Privilege Vulnerability",
            "summary": "Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.",
            "score": 7.2,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00678,
            "epssPercentile": 0.50038,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62911",
            "title": "Microsoft Exchange Server Elevation of Privilege Vulnerability",
            "summary": "Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "CISA Vulnrichment records proof-of-concept exploitation in its SSVC data. BlackTree has not independently executed or validated exploit material.",
            "epss": 0.01324,
            "epssPercentile": 0.69056,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62912",
            "title": "Microsoft Exchange Server Denial of Service Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01315,
            "epssPercentile": 0.68862,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62913",
            "title": "Microsoft Exchange Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00652,
            "epssPercentile": 0.48971,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62914",
            "title": "Microsoft Exchange Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00335,
            "epssPercentile": 0.26317,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62915",
            "title": "Microsoft Exchange Server Security Feature Bypass Vulnerability",
            "summary": "Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00484,
            "epssPercentile": 0.39964,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65813",
            "title": "Microsoft Exchange Server Elevation of Privilege Vulnerability",
            "summary": "Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0065,
            "epssPercentile": 0.48868,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-62913",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-esu-kb5121575",
      "slug": "microsoft-2026-08-esu-kb5121575",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5121575",
      "title": "Deploy Microsoft ESU security update KB5121575",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5121575",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft Exchange Server 2019 Cumulative Update 14",
      "platform": "ESU",
      "release_version": "15.02.1544.044",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 7 linked CVEs for Microsoft Exchange Server 2019 Cumulative Update 14.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 7,
        "ids": [
          "CVE-2026-62910",
          "CVE-2026-62911",
          "CVE-2026-62912",
          "CVE-2026-62913",
          "CVE-2026-62914",
          "CVE-2026-62915",
          "CVE-2026-65813"
        ],
        "details": [
          {
            "id": "CVE-2026-62910",
            "title": "Microsoft Exchange Server Elevation of Privilege Vulnerability",
            "summary": "Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.",
            "score": 7.2,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00678,
            "epssPercentile": 0.50038,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62911",
            "title": "Microsoft Exchange Server Elevation of Privilege Vulnerability",
            "summary": "Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "CISA Vulnrichment records proof-of-concept exploitation in its SSVC data. BlackTree has not independently executed or validated exploit material.",
            "epss": 0.01324,
            "epssPercentile": 0.69056,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62912",
            "title": "Microsoft Exchange Server Denial of Service Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01315,
            "epssPercentile": 0.68862,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62913",
            "title": "Microsoft Exchange Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00652,
            "epssPercentile": 0.48971,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62914",
            "title": "Microsoft Exchange Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00335,
            "epssPercentile": 0.26317,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62915",
            "title": "Microsoft Exchange Server Security Feature Bypass Vulnerability",
            "summary": "Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00484,
            "epssPercentile": 0.39964,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65813",
            "title": "Microsoft Exchange Server Elevation of Privilege Vulnerability",
            "summary": "Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0065,
            "epssPercentile": 0.48868,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-62913",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-esu-kb5121576",
      "slug": "microsoft-2026-08-esu-kb5121576",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5121576",
      "title": "Deploy Microsoft ESU security update KB5121576",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5121576",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft Exchange Server 2016 Cumulative Update 23",
      "platform": "ESU",
      "release_version": "15.01.2507.072",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 7 linked CVEs for Microsoft Exchange Server 2016 Cumulative Update 23.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 7,
        "ids": [
          "CVE-2026-62910",
          "CVE-2026-62911",
          "CVE-2026-62912",
          "CVE-2026-62913",
          "CVE-2026-62914",
          "CVE-2026-62915",
          "CVE-2026-65813"
        ],
        "details": [
          {
            "id": "CVE-2026-62910",
            "title": "Microsoft Exchange Server Elevation of Privilege Vulnerability",
            "summary": "Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.",
            "score": 7.2,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00678,
            "epssPercentile": 0.50038,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62911",
            "title": "Microsoft Exchange Server Elevation of Privilege Vulnerability",
            "summary": "Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "CISA Vulnrichment records proof-of-concept exploitation in its SSVC data. BlackTree has not independently executed or validated exploit material.",
            "epss": 0.01324,
            "epssPercentile": 0.69056,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62912",
            "title": "Microsoft Exchange Server Denial of Service Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01315,
            "epssPercentile": 0.68862,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62913",
            "title": "Microsoft Exchange Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00652,
            "epssPercentile": 0.48971,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62914",
            "title": "Microsoft Exchange Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00335,
            "epssPercentile": 0.26317,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62915",
            "title": "Microsoft Exchange Server Security Feature Bypass Vulnerability",
            "summary": "Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00484,
            "epssPercentile": 0.39964,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65813",
            "title": "Microsoft Exchange Server Elevation of Privilege Vulnerability",
            "summary": "Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0065,
            "epssPercentile": 0.48868,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-62913",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-microsoft-dynamics-kb5100263",
      "slug": "microsoft-2026-08-microsoft-dynamics-kb5100263",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5100263",
      "title": "Deploy Microsoft Microsoft Dynamics security update KB5100263",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5100263",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft Dynamics 365 Business Central Release Wave 1 2025",
      "platform": "Microsoft Dynamics",
      "release_version": "26.0.50788",
      "action_type": "deploy-patch",
      "restart_required": "no",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Dynamics 365 Business Central Release Wave 1 2025.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-40375"
        ],
        "details": [
          {
            "id": "CVE-2026-40375",
            "title": "Microsoft Dynamics Business Central Information Disclosure Vulnerability",
            "summary": "Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00769,
            "epssPercentile": 0.53258,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 6.5,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-40375",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "The reviewed source does not require a restart.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-microsoft-dynamics-kb5100265",
      "slug": "microsoft-2026-08-microsoft-dynamics-kb5100265",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5100265",
      "title": "Deploy Microsoft Microsoft Dynamics security update KB5100265",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5100265",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft Dynamics 365 Business Central Release Wave 2 2025",
      "platform": "Microsoft Dynamics",
      "release_version": "27.0.50789",
      "action_type": "deploy-patch",
      "restart_required": "no",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Dynamics 365 Business Central Release Wave 2 2025.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-40375"
        ],
        "details": [
          {
            "id": "CVE-2026-40375",
            "title": "Microsoft Dynamics Business Central Information Disclosure Vulnerability",
            "summary": "Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00769,
            "epssPercentile": 0.53258,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 6.5,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-40375",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "The reviewed source does not require a restart.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-microsoft-dynamics-kb5100266",
      "slug": "microsoft-2026-08-microsoft-dynamics-kb5100266",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5100266",
      "title": "Deploy Microsoft Microsoft Dynamics security update KB5100266",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5100266",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft Dynamics 365 Business Central 2026 Release Wave 1",
      "platform": "Microsoft Dynamics",
      "release_version": "28.0.50938",
      "action_type": "deploy-patch",
      "restart_required": "no",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Dynamics 365 Business Central 2026 Release Wave 1.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-40375"
        ],
        "details": [
          {
            "id": "CVE-2026-40375",
            "title": "Microsoft Dynamics Business Central Information Disclosure Vulnerability",
            "summary": "Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00769,
            "epssPercentile": 0.53258,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 6.5,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-40375",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "The reviewed source does not require a restart.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-microsoft-dynamics-msrc-2026-08-microsoft-dynamics-release-notes-microsoft-dynamics-365-on-premises-version-9-1",
      "slug": "microsoft-2026-08-microsoft-dynamics-msrc-2026-08-microsoft-dynamics-release-notes-microsoft-dynamics-365-on-premises-version-9-1",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-08-microsoft-dynamics-release-notes",
      "title": "Deploy Microsoft Microsoft Dynamics update for Microsoft Dynamics 365 (on-premises) version 9.1",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://www.microsoft.com/en-us/download/details.aspx?id=108757",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft Dynamics 365 (on-premises) version 9.1",
      "platform": "Microsoft Dynamics",
      "release_version": "9.1.0047.0006",
      "action_type": "deploy-patch",
      "restart_required": "no",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Microsoft Dynamics 365 (on-premises) version 9.1.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 2,
        "ids": [
          "CVE-2026-65815",
          "CVE-2026-66301"
        ],
        "details": [
          {
            "id": "CVE-2026-65815",
            "title": "Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.5829,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66301",
            "title": "Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00684,
            "epssPercentile": 0.50254,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-65815",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "The reviewed source does not require a restart.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-microsoft-office-kb5002755",
      "slug": "microsoft-2026-08-microsoft-office-kb5002755",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002755",
      "title": "Deploy Microsoft Microsoft Office security update KB5002755",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002755",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft Outlook 2016 (32-bit edition), Microsoft Outlook 2016 (64-bit edition)",
      "platform": "Microsoft Office",
      "release_version": "16.0.5565.1000",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft Outlook 2016 (32-bit edition), Microsoft Outlook 2016 (64-bit edition).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 3,
        "ids": [
          "CVE-2026-62882",
          "CVE-2026-63518",
          "CVE-2026-70329"
        ],
        "details": [
          {
            "id": "CVE-2026-62882",
            "title": "Microsoft Outlook Spoofing Vulnerability",
            "summary": "Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00617,
            "epssPercentile": 0.47348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63518",
            "title": "Microsoft Office Word Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00352,
            "epssPercentile": 0.28155,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70329",
            "title": "Microsoft Outlook Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49646,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-70329",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-microsoft-office-kb5002791",
      "slug": "microsoft-2026-08-microsoft-office-kb5002791",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002791",
      "title": "Deploy Microsoft Microsoft Office security update KB5002791",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002791",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition)",
      "platform": "Microsoft Office",
      "release_version": "16.0.5565.1000",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-65661"
        ],
        "details": [
          {
            "id": "CVE-2026-65661",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25182,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-65661",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-microsoft-office-kb5002795",
      "slug": "microsoft-2026-08-microsoft-office-kb5002795",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002795",
      "title": "Deploy Microsoft Microsoft Office security update KB5002795",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002795",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition)",
      "platform": "Microsoft Office",
      "release_version": "16.0.5565.1000",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-65661"
        ],
        "details": [
          {
            "id": "CVE-2026-65661",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25182,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-65661",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-microsoft-office-kb5002813",
      "slug": "microsoft-2026-08-microsoft-office-kb5002813",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002813",
      "title": "Deploy Microsoft Microsoft Office security update KB5002813",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002813",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft Access 2016 (32-bit edition), Microsoft Access 2016 (64-bit edition)",
      "platform": "Microsoft Office",
      "release_version": "16.0.5565.1000",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Access 2016 (32-bit edition), Microsoft Access 2016 (64-bit edition).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-64914"
        ],
        "details": [
          {
            "id": "CVE-2026-64914",
            "title": "Microsoft Access Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33696,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-64914",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-microsoft-office-kb5002832",
      "slug": "microsoft-2026-08-microsoft-office-kb5002832",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002832",
      "title": "Deploy Microsoft Microsoft Office security update KB5002832",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002832",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft Access 2016 (32-bit edition), Microsoft Access 2016 (64-bit edition)",
      "platform": "Microsoft Office",
      "release_version": "16.0.5565.1000",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 5 linked CVEs for Microsoft Access 2016 (32-bit edition), Microsoft Access 2016 (64-bit edition).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 5,
        "ids": [
          "CVE-2026-64906",
          "CVE-2026-64908",
          "CVE-2026-64912",
          "CVE-2026-64919",
          "CVE-2026-64920"
        ],
        "details": [
          {
            "id": "CVE-2026-64906",
            "title": "Microsoft Access Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22638,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64908",
            "title": "Microsoft Access Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22641,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64912",
            "title": "Microsoft Access Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22641,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64919",
            "title": "Microsoft Access Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.2264,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64920",
            "title": "Microsoft Access Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.2264,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-64920",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-microsoft-office-kb5002884",
      "slug": "microsoft-2026-08-microsoft-office-kb5002884",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002884",
      "title": "Deploy Microsoft Microsoft Office security update KB5002884",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002884",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Office Online Server",
      "platform": "Microsoft Office",
      "release_version": "16.0.10417.20175",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 25 linked CVEs for Office Online Server.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 25,
        "ids": [
          "CVE-2026-65807",
          "CVE-2026-68793",
          "CVE-2026-68794",
          "CVE-2026-68795",
          "CVE-2026-68796",
          "CVE-2026-68797",
          "CVE-2026-68799",
          "CVE-2026-68800",
          "CVE-2026-68801",
          "CVE-2026-68802",
          "CVE-2026-68803",
          "CVE-2026-68804",
          "CVE-2026-68805",
          "CVE-2026-68806",
          "CVE-2026-68807",
          "CVE-2026-68808",
          "CVE-2026-68810",
          "CVE-2026-68811",
          "CVE-2026-68812",
          "CVE-2026-68814",
          "CVE-2026-68815",
          "CVE-2026-68816",
          "CVE-2026-68817",
          "CVE-2026-70327",
          "CVE-2026-70328"
        ],
        "details": [
          {
            "id": "CVE-2026-65807",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00442,
            "epssPercentile": 0.37048,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68793",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25182,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68794",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00352,
            "epssPercentile": 0.28156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68795",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25183,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68796",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25182,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68797",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00447,
            "epssPercentile": 0.37485,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68799",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.27419,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68800",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25183,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68801",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25183,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68802",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.27418,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68803",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22639,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68804",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00352,
            "epssPercentile": 0.28155,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68805",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25181,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68806",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds write in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00393,
            "epssPercentile": 0.32536,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68807",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.2264,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68808",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.27421,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68810",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22642,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68811",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22639,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68812",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33695,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68814",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33696,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68815",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22642,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68816",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26934,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68817",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33696,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70327",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00853,
            "epssPercentile": 0.55907,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70328",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00853,
            "epssPercentile": 0.55907,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-65807",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-microsoft-office-kb5002893",
      "slug": "microsoft-2026-08-microsoft-office-kb5002893",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002893",
      "title": "Deploy Microsoft Microsoft Office security update KB5002893",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002893",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft SharePoint Server Subscription Edition",
      "platform": "Microsoft Office",
      "release_version": "16.0.19725.20522",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 29 linked CVEs for Microsoft SharePoint Server Subscription Edition.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 29,
        "ids": [
          "CVE-2026-57105",
          "CVE-2026-58639",
          "CVE-2026-62827",
          "CVE-2026-62829",
          "CVE-2026-62837",
          "CVE-2026-62839",
          "CVE-2026-62917",
          "CVE-2026-63512",
          "CVE-2026-63514",
          "CVE-2026-63516",
          "CVE-2026-63520",
          "CVE-2026-64897",
          "CVE-2026-64900",
          "CVE-2026-64901",
          "CVE-2026-64902",
          "CVE-2026-64916",
          "CVE-2026-64921",
          "CVE-2026-64922",
          "CVE-2026-65658",
          "CVE-2026-65660",
          "CVE-2026-65663",
          "CVE-2026-65665",
          "CVE-2026-66805",
          "CVE-2026-66808",
          "CVE-2026-70306",
          "CVE-2026-70321",
          "CVE-2026-70324",
          "CVE-2026-70326",
          "CVE-2026-70355"
        ],
        "details": [
          {
            "id": "CVE-2026-57105",
            "title": "Microsoft Office SharePoint Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0058,
            "epssPercentile": 0.45587,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58639",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00835,
            "epssPercentile": 0.55344,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62827",
            "title": "Microsoft SharePoint Server Elevation of Privilege Vulnerability",
            "summary": "Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0073,
            "epssPercentile": 0.5192,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62829",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00356,
            "epssPercentile": 0.28692,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62837",
            "title": "Microsoft SharePoint Server Information Disclosure Vulnerability",
            "summary": "Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00861,
            "epssPercentile": 0.5619,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62839",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00626,
            "epssPercentile": 0.47793,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62917",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36752,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63512",
            "title": "Microsoft SharePoint Server Tampering Vulnerability",
            "summary": "Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00545,
            "epssPercentile": 0.43741,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63514",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01517,
            "epssPercentile": 0.72871,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63516",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01346,
            "epssPercentile": 0.69579,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63520",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02893,
            "epssPercentile": 0.86002,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64897",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00412,
            "epssPercentile": 0.34452,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64900",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00446,
            "epssPercentile": 0.37439,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64901",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01908,
            "epssPercentile": 0.78406,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64902",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00412,
            "epssPercentile": 0.34452,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64916",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00412,
            "epssPercentile": 0.34451,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64921",
            "title": "Microsoft SharePoint Server Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00995,
            "epssPercentile": 0.60378,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64922",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00412,
            "epssPercentile": 0.34452,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65658",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01385,
            "epssPercentile": 0.70409,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65660",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00807,
            "epssPercentile": 0.5448,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65663",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01385,
            "epssPercentile": 0.70409,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65665",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02769,
            "epssPercentile": 0.85358,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66805",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01546,
            "epssPercentile": 0.73356,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66808",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.011,
            "epssPercentile": 0.63479,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70306",
            "title": "Microsoft Office SharePoint Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.",
            "score": 9.3,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00749,
            "epssPercentile": 0.52571,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70321",
            "title": "Microsoft SharePoint Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01281,
            "epssPercentile": 0.68139,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70324",
            "title": "Microsoft SharePoint Elevation of Privilege Vulnerability",
            "summary": "Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00696,
            "epssPercentile": 0.50694,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70326",
            "title": "Microsoft SharePoint Server Elevation of Privilege Vulnerability",
            "summary": "Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00588,
            "epssPercentile": 0.4598,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70355",
            "title": "Microsoft SharePoint Server Elevation of Privilege Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00462,
            "epssPercentile": 0.38533,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-70306",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-microsoft-office-kb5002894",
      "slug": "microsoft-2026-08-microsoft-office-kb5002894",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002894",
      "title": "Deploy Microsoft Microsoft Office security update KB5002894",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002894",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft SharePoint Server 2019",
      "platform": "Microsoft Office",
      "release_version": "16.0.10417.20198",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 27 linked CVEs for Microsoft SharePoint Server 2019.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 27,
        "ids": [
          "CVE-2026-57105",
          "CVE-2026-58639",
          "CVE-2026-62827",
          "CVE-2026-62829",
          "CVE-2026-62837",
          "CVE-2026-62839",
          "CVE-2026-62917",
          "CVE-2026-63512",
          "CVE-2026-63514",
          "CVE-2026-63516",
          "CVE-2026-63520",
          "CVE-2026-64897",
          "CVE-2026-64900",
          "CVE-2026-64901",
          "CVE-2026-64902",
          "CVE-2026-64916",
          "CVE-2026-64921",
          "CVE-2026-64922",
          "CVE-2026-65658",
          "CVE-2026-65660",
          "CVE-2026-65663",
          "CVE-2026-65665",
          "CVE-2026-66805",
          "CVE-2026-66808",
          "CVE-2026-70306",
          "CVE-2026-70324",
          "CVE-2026-70355"
        ],
        "details": [
          {
            "id": "CVE-2026-57105",
            "title": "Microsoft Office SharePoint Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0058,
            "epssPercentile": 0.45587,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58639",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00835,
            "epssPercentile": 0.55344,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62827",
            "title": "Microsoft SharePoint Server Elevation of Privilege Vulnerability",
            "summary": "Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0073,
            "epssPercentile": 0.5192,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62829",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00356,
            "epssPercentile": 0.28692,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62837",
            "title": "Microsoft SharePoint Server Information Disclosure Vulnerability",
            "summary": "Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00861,
            "epssPercentile": 0.5619,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62839",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00626,
            "epssPercentile": 0.47793,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62917",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36752,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63512",
            "title": "Microsoft SharePoint Server Tampering Vulnerability",
            "summary": "Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00545,
            "epssPercentile": 0.43741,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63514",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01517,
            "epssPercentile": 0.72871,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63516",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01346,
            "epssPercentile": 0.69579,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63520",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02893,
            "epssPercentile": 0.86002,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64897",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00412,
            "epssPercentile": 0.34452,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64900",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00446,
            "epssPercentile": 0.37439,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64901",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01908,
            "epssPercentile": 0.78406,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64902",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00412,
            "epssPercentile": 0.34452,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64916",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00412,
            "epssPercentile": 0.34451,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64921",
            "title": "Microsoft SharePoint Server Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00995,
            "epssPercentile": 0.60378,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64922",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00412,
            "epssPercentile": 0.34452,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65658",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01385,
            "epssPercentile": 0.70409,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65660",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00807,
            "epssPercentile": 0.5448,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65663",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01385,
            "epssPercentile": 0.70409,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65665",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02769,
            "epssPercentile": 0.85358,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66805",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01546,
            "epssPercentile": 0.73356,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66808",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.011,
            "epssPercentile": 0.63479,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70306",
            "title": "Microsoft Office SharePoint Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.",
            "score": 9.3,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00749,
            "epssPercentile": 0.52571,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70324",
            "title": "Microsoft SharePoint Elevation of Privilege Vulnerability",
            "summary": "Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00696,
            "epssPercentile": 0.50694,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70355",
            "title": "Microsoft SharePoint Server Elevation of Privilege Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00462,
            "epssPercentile": 0.38533,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-70306",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-microsoft-office-kb5002896",
      "slug": "microsoft-2026-08-microsoft-office-kb5002896",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002896",
      "title": "Deploy Microsoft Microsoft Office security update KB5002896",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002896",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft SharePoint Server 2019",
      "platform": "Microsoft Office",
      "release_version": "16.0.10417.20198",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 26 linked CVEs for Microsoft SharePoint Server 2019.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 26,
        "ids": [
          "CVE-2026-57105",
          "CVE-2026-58639",
          "CVE-2026-62827",
          "CVE-2026-62829",
          "CVE-2026-62837",
          "CVE-2026-62839",
          "CVE-2026-62917",
          "CVE-2026-63512",
          "CVE-2026-63514",
          "CVE-2026-63516",
          "CVE-2026-63520",
          "CVE-2026-64897",
          "CVE-2026-64900",
          "CVE-2026-64901",
          "CVE-2026-64902",
          "CVE-2026-64916",
          "CVE-2026-64921",
          "CVE-2026-64922",
          "CVE-2026-65658",
          "CVE-2026-65660",
          "CVE-2026-65663",
          "CVE-2026-65665",
          "CVE-2026-66805",
          "CVE-2026-66808",
          "CVE-2026-70324",
          "CVE-2026-70355"
        ],
        "details": [
          {
            "id": "CVE-2026-57105",
            "title": "Microsoft Office SharePoint Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0058,
            "epssPercentile": 0.45587,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58639",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00835,
            "epssPercentile": 0.55344,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62827",
            "title": "Microsoft SharePoint Server Elevation of Privilege Vulnerability",
            "summary": "Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0073,
            "epssPercentile": 0.5192,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62829",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00356,
            "epssPercentile": 0.28692,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62837",
            "title": "Microsoft SharePoint Server Information Disclosure Vulnerability",
            "summary": "Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00861,
            "epssPercentile": 0.5619,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62839",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00626,
            "epssPercentile": 0.47793,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62917",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36752,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63512",
            "title": "Microsoft SharePoint Server Tampering Vulnerability",
            "summary": "Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00545,
            "epssPercentile": 0.43741,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63514",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01517,
            "epssPercentile": 0.72871,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63516",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01346,
            "epssPercentile": 0.69579,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63520",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02893,
            "epssPercentile": 0.86002,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64897",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00412,
            "epssPercentile": 0.34452,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64900",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00446,
            "epssPercentile": 0.37439,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64901",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01908,
            "epssPercentile": 0.78406,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64902",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00412,
            "epssPercentile": 0.34452,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64916",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00412,
            "epssPercentile": 0.34451,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64921",
            "title": "Microsoft SharePoint Server Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00995,
            "epssPercentile": 0.60378,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64922",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00412,
            "epssPercentile": 0.34452,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65658",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01385,
            "epssPercentile": 0.70409,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65660",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00807,
            "epssPercentile": 0.5448,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65663",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01385,
            "epssPercentile": 0.70409,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65665",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02769,
            "epssPercentile": 0.85358,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66805",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01546,
            "epssPercentile": 0.73356,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66808",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.011,
            "epssPercentile": 0.63479,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70324",
            "title": "Microsoft SharePoint Elevation of Privilege Vulnerability",
            "summary": "Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00696,
            "epssPercentile": 0.50694,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70355",
            "title": "Microsoft SharePoint Server Elevation of Privilege Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00462,
            "epssPercentile": 0.38533,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-70324",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-microsoft-office-kb5002897",
      "slug": "microsoft-2026-08-microsoft-office-kb5002897",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002897",
      "title": "Deploy Microsoft Microsoft Office security update KB5002897",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002897",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition)",
      "platform": "Microsoft Office",
      "release_version": "16.0.5565.1001",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 12 linked CVEs for Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 12,
        "ids": [
          "CVE-2026-63513",
          "CVE-2026-63517",
          "CVE-2026-63524",
          "CVE-2026-63526",
          "CVE-2026-63529",
          "CVE-2026-63532",
          "CVE-2026-63533",
          "CVE-2026-64899",
          "CVE-2026-64903",
          "CVE-2026-64909",
          "CVE-2026-65661",
          "CVE-2026-70317"
        ],
        "details": [
          {
            "id": "CVE-2026-63513",
            "title": "Microsoft Office Graphics Component Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00352,
            "epssPercentile": 0.28156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63517",
            "title": "Microsoft Office Graphics Component Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0036,
            "epssPercentile": 0.29099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63524",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.2742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63526",
            "title": "Microsoft Office Graphics Component Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26935,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63529",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.27419,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63532",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26935,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63533",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22639,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64899",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.27419,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64903",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26934,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64909",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26935,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65661",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25182,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70317",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29015,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-65661",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-microsoft-office-kb5002899",
      "slug": "microsoft-2026-08-microsoft-office-kb5002899",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002899",
      "title": "Deploy Microsoft Microsoft Office security update KB5002899",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002899",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft PowerPoint 2016 (32-bit edition), Microsoft PowerPoint 2016 (64-bit edition)",
      "platform": "Microsoft Office",
      "release_version": "16.0.5565.1001",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft PowerPoint 2016 (32-bit edition), Microsoft PowerPoint 2016 (64-bit edition).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-68809"
        ],
        "details": [
          {
            "id": "CVE-2026-68809",
            "title": "Powerpoint Information Disclosure Vulnerability",
            "summary": "Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00277,
            "epssPercentile": 0.1987,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 5.5,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-68809",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-microsoft-office-kb5002900",
      "slug": "microsoft-2026-08-microsoft-office-kb5002900",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002900",
      "title": "Deploy Microsoft Microsoft Office security update KB5002900",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002900",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition)",
      "platform": "Microsoft Office",
      "release_version": "16.0.5565.1000",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-65661"
        ],
        "details": [
          {
            "id": "CVE-2026-65661",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25182,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-65661",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-microsoft-office-kb5002901",
      "slug": "microsoft-2026-08-microsoft-office-kb5002901",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002901",
      "title": "Deploy Microsoft Microsoft Office security update KB5002901",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002901",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft Word 2016 (32-bit edition), Microsoft Word 2016 (64-bit edition)",
      "platform": "Microsoft Office",
      "release_version": "16.0.5565.1000",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 16 linked CVEs for Microsoft Word 2016 (32-bit edition), Microsoft Word 2016 (64-bit edition).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 16,
        "ids": [
          "CVE-2026-63521",
          "CVE-2026-63525",
          "CVE-2026-63527",
          "CVE-2026-63528",
          "CVE-2026-63530",
          "CVE-2026-63531",
          "CVE-2026-64905",
          "CVE-2026-64907",
          "CVE-2026-64915",
          "CVE-2026-64917",
          "CVE-2026-66806",
          "CVE-2026-66809",
          "CVE-2026-66810",
          "CVE-2026-70310",
          "CVE-2026-70311",
          "CVE-2026-70318"
        ],
        "details": [
          {
            "id": "CVE-2026-63521",
            "title": "Microsoft Office Word Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0029,
            "epssPercentile": 0.21187,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63525",
            "title": "Microsoft Office Word Remote Code Execution Vulnerability",
            "summary": "Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00377,
            "epssPercentile": 0.30824,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63527",
            "title": "Microsoft Office Word Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22641,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63528",
            "title": "Microsoft Office Word Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.27419,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63530",
            "title": "Microsoft Office Word Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00459,
            "epssPercentile": 0.38326,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63531",
            "title": "Microsoft Office Word Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.2742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64905",
            "title": "Microsoft Office Word Remote Code Execution Vulnerability",
            "summary": "Buffer over-read in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22638,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64907",
            "title": "Microsoft Office Word Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26933,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64915",
            "title": "Microsoft Office Word Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22641,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64917",
            "title": "Microsoft Office Word Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.2742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66806",
            "title": "Microsoft Office Word Information Disclosure Vulnerability",
            "summary": "Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00307,
            "epssPercentile": 0.23063,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66809",
            "title": "Microsoft Office Graphics Component Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00277,
            "epssPercentile": 0.19871,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66810",
            "title": "Microsoft Office Word Information Disclosure Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00277,
            "epssPercentile": 0.1987,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70310",
            "title": "Microsoft Word Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00277,
            "epssPercentile": 0.19871,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70311",
            "title": "Microsoft Office Word Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22638,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70318",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0036,
            "epssPercentile": 0.29099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-70311",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-microsoft-office-kb5002902",
      "slug": "microsoft-2026-08-microsoft-office-kb5002902",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002902",
      "title": "Deploy Microsoft Microsoft Office security update KB5002902",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002902",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition)",
      "platform": "Microsoft Office",
      "release_version": "16.0.5565.1001",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-63515"
        ],
        "details": [
          {
            "id": "CVE-2026-63515",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00352,
            "epssPercentile": 0.28156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-63515",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-microsoft-office-kb5002903",
      "slug": "microsoft-2026-08-microsoft-office-kb5002903",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002903",
      "title": "Deploy Microsoft Microsoft Office security update KB5002903",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002903",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft Excel 2016 (32-bit edition), Microsoft Excel 2016 (64-bit edition)",
      "platform": "Microsoft Office",
      "release_version": "16.0.5565.1001",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 25 linked CVEs for Microsoft Excel 2016 (32-bit edition), Microsoft Excel 2016 (64-bit edition).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 25,
        "ids": [
          "CVE-2026-65807",
          "CVE-2026-68793",
          "CVE-2026-68794",
          "CVE-2026-68795",
          "CVE-2026-68796",
          "CVE-2026-68797",
          "CVE-2026-68799",
          "CVE-2026-68800",
          "CVE-2026-68801",
          "CVE-2026-68802",
          "CVE-2026-68803",
          "CVE-2026-68804",
          "CVE-2026-68805",
          "CVE-2026-68806",
          "CVE-2026-68807",
          "CVE-2026-68808",
          "CVE-2026-68810",
          "CVE-2026-68811",
          "CVE-2026-68812",
          "CVE-2026-68814",
          "CVE-2026-68815",
          "CVE-2026-68816",
          "CVE-2026-68817",
          "CVE-2026-70327",
          "CVE-2026-70328"
        ],
        "details": [
          {
            "id": "CVE-2026-65807",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00442,
            "epssPercentile": 0.37048,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68793",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25182,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68794",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00352,
            "epssPercentile": 0.28156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68795",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25183,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68796",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25182,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68797",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00447,
            "epssPercentile": 0.37485,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68799",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.27419,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68800",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25183,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68801",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25183,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68802",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.27418,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68803",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22639,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68804",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00352,
            "epssPercentile": 0.28155,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68805",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25181,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68806",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds write in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00393,
            "epssPercentile": 0.32536,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68807",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.2264,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68808",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.27421,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68810",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22642,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68811",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22639,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68812",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33695,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68814",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33696,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68815",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22642,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68816",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26934,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68817",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33696,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70327",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00853,
            "epssPercentile": 0.55907,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70328",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00853,
            "epssPercentile": 0.55907,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-65807",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-microsoft-office-kb5002905",
      "slug": "microsoft-2026-08-microsoft-office-kb5002905",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002905",
      "title": "Deploy Microsoft Microsoft Office security update KB5002905",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002905",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "platform": "Microsoft Office",
      "release_version": "16.0.5565.1001",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 23 linked CVEs for Microsoft SharePoint Enterprise Server 2016.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 23,
        "ids": [
          "CVE-2026-58639",
          "CVE-2026-62827",
          "CVE-2026-62837",
          "CVE-2026-62839",
          "CVE-2026-62917",
          "CVE-2026-63512",
          "CVE-2026-63514",
          "CVE-2026-63516",
          "CVE-2026-63520",
          "CVE-2026-64897",
          "CVE-2026-64900",
          "CVE-2026-64901",
          "CVE-2026-64902",
          "CVE-2026-64916",
          "CVE-2026-64921",
          "CVE-2026-64922",
          "CVE-2026-65658",
          "CVE-2026-65660",
          "CVE-2026-65663",
          "CVE-2026-66805",
          "CVE-2026-66808",
          "CVE-2026-70306",
          "CVE-2026-70324"
        ],
        "details": [
          {
            "id": "CVE-2026-58639",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00835,
            "epssPercentile": 0.55344,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62827",
            "title": "Microsoft SharePoint Server Elevation of Privilege Vulnerability",
            "summary": "Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0073,
            "epssPercentile": 0.5192,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62837",
            "title": "Microsoft SharePoint Server Information Disclosure Vulnerability",
            "summary": "Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00861,
            "epssPercentile": 0.5619,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62839",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00626,
            "epssPercentile": 0.47793,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62917",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36752,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63512",
            "title": "Microsoft SharePoint Server Tampering Vulnerability",
            "summary": "Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00545,
            "epssPercentile": 0.43741,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63514",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01517,
            "epssPercentile": 0.72871,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63516",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01346,
            "epssPercentile": 0.69579,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63520",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02893,
            "epssPercentile": 0.86002,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64897",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00412,
            "epssPercentile": 0.34452,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64900",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00446,
            "epssPercentile": 0.37439,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64901",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01908,
            "epssPercentile": 0.78406,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64902",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00412,
            "epssPercentile": 0.34452,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64916",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00412,
            "epssPercentile": 0.34451,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64921",
            "title": "Microsoft SharePoint Server Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00995,
            "epssPercentile": 0.60378,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64922",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00412,
            "epssPercentile": 0.34452,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65658",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01385,
            "epssPercentile": 0.70409,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65660",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00807,
            "epssPercentile": 0.5448,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65663",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01385,
            "epssPercentile": 0.70409,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66805",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01546,
            "epssPercentile": 0.73356,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66808",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.011,
            "epssPercentile": 0.63479,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70306",
            "title": "Microsoft Office SharePoint Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.",
            "score": 9.3,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00749,
            "epssPercentile": 0.52571,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70324",
            "title": "Microsoft SharePoint Elevation of Privilege Vulnerability",
            "summary": "Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00696,
            "epssPercentile": 0.50694,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-70306",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-microsoft-office-kb5002906",
      "slug": "microsoft-2026-08-microsoft-office-kb5002906",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002906",
      "title": "Deploy Microsoft Microsoft Office security update KB5002906",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002906",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "platform": "Microsoft Office",
      "release_version": "16.0.5565.1001",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 22 linked CVEs for Microsoft SharePoint Enterprise Server 2016.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 22,
        "ids": [
          "CVE-2026-58639",
          "CVE-2026-62827",
          "CVE-2026-62837",
          "CVE-2026-62839",
          "CVE-2026-62917",
          "CVE-2026-63512",
          "CVE-2026-63514",
          "CVE-2026-63516",
          "CVE-2026-63520",
          "CVE-2026-64897",
          "CVE-2026-64900",
          "CVE-2026-64901",
          "CVE-2026-64902",
          "CVE-2026-64916",
          "CVE-2026-64921",
          "CVE-2026-64922",
          "CVE-2026-65658",
          "CVE-2026-65660",
          "CVE-2026-65663",
          "CVE-2026-66805",
          "CVE-2026-66808",
          "CVE-2026-70324"
        ],
        "details": [
          {
            "id": "CVE-2026-58639",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00835,
            "epssPercentile": 0.55344,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62827",
            "title": "Microsoft SharePoint Server Elevation of Privilege Vulnerability",
            "summary": "Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0073,
            "epssPercentile": 0.5192,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62837",
            "title": "Microsoft SharePoint Server Information Disclosure Vulnerability",
            "summary": "Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00861,
            "epssPercentile": 0.5619,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62839",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00626,
            "epssPercentile": 0.47793,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62917",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36752,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63512",
            "title": "Microsoft SharePoint Server Tampering Vulnerability",
            "summary": "Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00545,
            "epssPercentile": 0.43741,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63514",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01517,
            "epssPercentile": 0.72871,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63516",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01346,
            "epssPercentile": 0.69579,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63520",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02893,
            "epssPercentile": 0.86002,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64897",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00412,
            "epssPercentile": 0.34452,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64900",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00446,
            "epssPercentile": 0.37439,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64901",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01908,
            "epssPercentile": 0.78406,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64902",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00412,
            "epssPercentile": 0.34452,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64916",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00412,
            "epssPercentile": 0.34451,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64921",
            "title": "Microsoft SharePoint Server Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00995,
            "epssPercentile": 0.60378,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64922",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00412,
            "epssPercentile": 0.34452,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65658",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01385,
            "epssPercentile": 0.70409,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65660",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00807,
            "epssPercentile": 0.5448,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65663",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01385,
            "epssPercentile": 0.70409,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66805",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01546,
            "epssPercentile": 0.73356,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66808",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.011,
            "epssPercentile": 0.63479,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70324",
            "title": "Microsoft SharePoint Elevation of Privilege Vulnerability",
            "summary": "Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00696,
            "epssPercentile": 0.50694,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-70324",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-microsoft-office-msrc-2026-08-microsoft-office-click-to-run-microsoft-365-apps-for-enterprise-for-32-bit-systems-microsoft-365-apps-for-enterprise-for-64-bit-systems-micr",
      "slug": "microsoft-2026-08-microsoft-office-msrc-2026-08-microsoft-office-click-to-run-microsoft-365-apps-for-enterprise-for-32-bit-systems-microsoft-365-apps-for-enterprise-for-64-bit-systems-micr",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-08-microsoft-office-click-to-run",
      "title": "Deploy Microsoft Microsoft Office update for Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office 2019 for 32-bit editions, plus 5 more",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://msrc.microsoft.com/update-guide/releaseNote/2026-Aug",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office 2019 for 32-bit editions, plus 5 more",
      "platform": "Microsoft Office",
      "release_version": "https://aka.ms/OfficeSecurityReleases",
      "action_type": "deploy-patch",
      "restart_required": "no",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 89 linked CVEs for Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office 2019 for 32-bit editions, plus 5 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 89,
        "ids": [
          "CVE-2026-58651",
          "CVE-2026-62842",
          "CVE-2026-62882",
          "CVE-2026-63513",
          "CVE-2026-63515",
          "CVE-2026-63517",
          "CVE-2026-63518",
          "CVE-2026-63519",
          "CVE-2026-63521",
          "CVE-2026-63524",
          "CVE-2026-63525",
          "CVE-2026-63526",
          "CVE-2026-63527",
          "CVE-2026-63528",
          "CVE-2026-63529",
          "CVE-2026-63530",
          "CVE-2026-63531",
          "CVE-2026-63532",
          "CVE-2026-63533",
          "CVE-2026-64898",
          "CVE-2026-64899",
          "CVE-2026-64903",
          "CVE-2026-64904",
          "CVE-2026-64905",
          "CVE-2026-64906",
          "CVE-2026-64907",
          "CVE-2026-64908",
          "CVE-2026-64909",
          "CVE-2026-64910",
          "CVE-2026-64911",
          "CVE-2026-64912",
          "CVE-2026-64914",
          "CVE-2026-64915",
          "CVE-2026-64917",
          "CVE-2026-64919",
          "CVE-2026-64920",
          "CVE-2026-65656",
          "CVE-2026-65657",
          "CVE-2026-65661",
          "CVE-2026-65664",
          "CVE-2026-65807",
          "CVE-2026-66806",
          "CVE-2026-66807",
          "CVE-2026-66809",
          "CVE-2026-66810",
          "CVE-2026-68792",
          "CVE-2026-68793",
          "CVE-2026-68794",
          "CVE-2026-68795",
          "CVE-2026-68796",
          "CVE-2026-68797",
          "CVE-2026-68798",
          "CVE-2026-68799",
          "CVE-2026-68800",
          "CVE-2026-68801",
          "CVE-2026-68802",
          "CVE-2026-68803",
          "CVE-2026-68804",
          "CVE-2026-68805",
          "CVE-2026-68806",
          "CVE-2026-68807",
          "CVE-2026-68808",
          "CVE-2026-68809",
          "CVE-2026-68810",
          "CVE-2026-68811",
          "CVE-2026-68812",
          "CVE-2026-68813",
          "CVE-2026-68814",
          "CVE-2026-68815",
          "CVE-2026-68816",
          "CVE-2026-68817",
          "CVE-2026-70130",
          "CVE-2026-70310",
          "CVE-2026-70311",
          "CVE-2026-70312",
          "CVE-2026-70313",
          "CVE-2026-70314",
          "CVE-2026-70315",
          "CVE-2026-70316",
          "CVE-2026-70317",
          "CVE-2026-70318",
          "CVE-2026-70319",
          "CVE-2026-70320",
          "CVE-2026-70322",
          "CVE-2026-70323",
          "CVE-2026-70325",
          "CVE-2026-70327",
          "CVE-2026-70328",
          "CVE-2026-70329"
        ],
        "details": [
          {
            "id": "CVE-2026-58651",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33695,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62842",
            "title": "Microsoft Office Graphics Component Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0036,
            "epssPercentile": 0.29099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62882",
            "title": "Microsoft Outlook Spoofing Vulnerability",
            "summary": "Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00617,
            "epssPercentile": 0.47348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63513",
            "title": "Microsoft Office Graphics Component Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00352,
            "epssPercentile": 0.28156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63515",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00352,
            "epssPercentile": 0.28156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63517",
            "title": "Microsoft Office Graphics Component Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0036,
            "epssPercentile": 0.29099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63518",
            "title": "Microsoft Office Word Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00352,
            "epssPercentile": 0.28155,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63519",
            "title": "Microsoft Office Graphics Component Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00352,
            "epssPercentile": 0.28156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63521",
            "title": "Microsoft Office Word Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0029,
            "epssPercentile": 0.21187,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63524",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.2742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63525",
            "title": "Microsoft Office Word Remote Code Execution Vulnerability",
            "summary": "Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00377,
            "epssPercentile": 0.30824,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63526",
            "title": "Microsoft Office Graphics Component Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26935,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63527",
            "title": "Microsoft Office Word Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22641,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63528",
            "title": "Microsoft Office Word Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.27419,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63529",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.27419,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63530",
            "title": "Microsoft Office Word Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00459,
            "epssPercentile": 0.38326,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63531",
            "title": "Microsoft Office Word Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.2742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63532",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26935,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63533",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22639,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64898",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26934,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64899",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.27419,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64903",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26934,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64904",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.2264,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64905",
            "title": "Microsoft Office Word Remote Code Execution Vulnerability",
            "summary": "Buffer over-read in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22638,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64906",
            "title": "Microsoft Access Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22638,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64907",
            "title": "Microsoft Office Word Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26933,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64908",
            "title": "Microsoft Access Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22641,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64909",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26935,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64910",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26934,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64911",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26935,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64912",
            "title": "Microsoft Access Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22641,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64914",
            "title": "Microsoft Access Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33696,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64915",
            "title": "Microsoft Office Word Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22641,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64917",
            "title": "Microsoft Office Word Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.2742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64919",
            "title": "Microsoft Access Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.2264,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64920",
            "title": "Microsoft Access Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.2264,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65656",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00356,
            "epssPercentile": 0.28679,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65657",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00439,
            "epssPercentile": 0.36836,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65661",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25182,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65664",
            "title": "Microsoft Office Graphics Component Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00352,
            "epssPercentile": 0.28155,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65807",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00442,
            "epssPercentile": 0.37048,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66806",
            "title": "Microsoft Office Word Information Disclosure Vulnerability",
            "summary": "Off-by-one error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00307,
            "epssPercentile": 0.23063,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66807",
            "title": "Microsoft Office Graphics Component Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00352,
            "epssPercentile": 0.28155,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66809",
            "title": "Microsoft Office Graphics Component Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00277,
            "epssPercentile": 0.19871,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66810",
            "title": "Microsoft Office Word Information Disclosure Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00277,
            "epssPercentile": 0.1987,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68792",
            "title": "Microsoft Office Elevation of Privilege Vulnerability",
            "summary": "Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00249,
            "epssPercentile": 0.16131,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68793",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25182,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68794",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00352,
            "epssPercentile": 0.28156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68795",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25183,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68796",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25182,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68797",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00447,
            "epssPercentile": 0.37485,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68798",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00421,
            "epssPercentile": 0.35358,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68799",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.27419,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68800",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25183,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68801",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25183,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68802",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.27418,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68803",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22639,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68804",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00352,
            "epssPercentile": 0.28155,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68805",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25181,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68806",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds write in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00393,
            "epssPercentile": 0.32536,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68807",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.2264,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68808",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.27421,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68809",
            "title": "Powerpoint Information Disclosure Vulnerability",
            "summary": "Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00277,
            "epssPercentile": 0.1987,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68810",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22642,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68811",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22639,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68812",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33695,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68813",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.2742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68814",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33696,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68815",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22642,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68816",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26934,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68817",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33696,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70130",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00323,
            "epssPercentile": 0.24917,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70310",
            "title": "Microsoft Word Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00277,
            "epssPercentile": 0.19871,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70311",
            "title": "Microsoft Office Word Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22638,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70312",
            "title": "Powerpoint Information Disclosure Vulnerability",
            "summary": "Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00277,
            "epssPercentile": 0.1987,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70313",
            "title": "Microsoft PowerPoint Remote Code Execution Vulnerability",
            "summary": "Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25182,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70314",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00467,
            "epssPercentile": 0.38833,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70315",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00375,
            "epssPercentile": 0.30683,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70316",
            "title": "Powerpoint Information Disclosure Vulnerability",
            "summary": "Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00375,
            "epssPercentile": 0.30685,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70317",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29015,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70318",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0036,
            "epssPercentile": 0.29099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70319",
            "title": "Microsoft Office Word Information Disclosure Vulnerability",
            "summary": "Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00375,
            "epssPercentile": 0.30683,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70320",
            "title": "Powerpoint Information Disclosure Vulnerability",
            "summary": "Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00375,
            "epssPercentile": 0.30684,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70322",
            "title": "Powerpoint Information Disclosure Vulnerability",
            "summary": "Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00375,
            "epssPercentile": 0.30684,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70323",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00375,
            "epssPercentile": 0.30684,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70325",
            "title": "Powerpoint Information Disclosure Vulnerability",
            "summary": "Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00375,
            "epssPercentile": 0.30684,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70327",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00853,
            "epssPercentile": 0.55907,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70328",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00853,
            "epssPercentile": 0.55907,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70329",
            "title": "Microsoft Outlook Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49646,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-70329",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "The reviewed source does not require a restart.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-microsoft-office-msrc-2026-08-microsoft-office-release-notes-microsoft-office-365-for-mac",
      "slug": "microsoft-2026-08-microsoft-office-msrc-2026-08-microsoft-office-release-notes-microsoft-office-365-for-mac",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-08-microsoft-office-release-notes",
      "title": "Deploy Microsoft Microsoft Office update for Microsoft Office 365 for Mac",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://www.microsoft.com/en-us/microsoft-365/mac/microsoft-365-for-mac?msockid=35f9adb0e74b61392038b90de6fe608c",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft Office 365 for Mac",
      "platform": "Microsoft Office",
      "release_version": "16.112.26081010",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 72 linked CVEs for Microsoft Office 365 for Mac.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 72,
        "ids": [
          "CVE-2026-58651",
          "CVE-2026-62842",
          "CVE-2026-63513",
          "CVE-2026-63515",
          "CVE-2026-63517",
          "CVE-2026-63518",
          "CVE-2026-63519",
          "CVE-2026-63524",
          "CVE-2026-63526",
          "CVE-2026-63527",
          "CVE-2026-63528",
          "CVE-2026-63530",
          "CVE-2026-63531",
          "CVE-2026-63532",
          "CVE-2026-63533",
          "CVE-2026-64898",
          "CVE-2026-64899",
          "CVE-2026-64903",
          "CVE-2026-64904",
          "CVE-2026-64905",
          "CVE-2026-64907",
          "CVE-2026-64909",
          "CVE-2026-64910",
          "CVE-2026-64911",
          "CVE-2026-64915",
          "CVE-2026-64917",
          "CVE-2026-65657",
          "CVE-2026-65664",
          "CVE-2026-65807",
          "CVE-2026-66807",
          "CVE-2026-66809",
          "CVE-2026-66810",
          "CVE-2026-68793",
          "CVE-2026-68794",
          "CVE-2026-68795",
          "CVE-2026-68796",
          "CVE-2026-68797",
          "CVE-2026-68798",
          "CVE-2026-68799",
          "CVE-2026-68800",
          "CVE-2026-68801",
          "CVE-2026-68802",
          "CVE-2026-68803",
          "CVE-2026-68804",
          "CVE-2026-68805",
          "CVE-2026-68806",
          "CVE-2026-68807",
          "CVE-2026-68808",
          "CVE-2026-68810",
          "CVE-2026-68811",
          "CVE-2026-68812",
          "CVE-2026-68813",
          "CVE-2026-68814",
          "CVE-2026-68815",
          "CVE-2026-68816",
          "CVE-2026-68817",
          "CVE-2026-70310",
          "CVE-2026-70311",
          "CVE-2026-70312",
          "CVE-2026-70313",
          "CVE-2026-70314",
          "CVE-2026-70315",
          "CVE-2026-70316",
          "CVE-2026-70317",
          "CVE-2026-70318",
          "CVE-2026-70319",
          "CVE-2026-70320",
          "CVE-2026-70322",
          "CVE-2026-70323",
          "CVE-2026-70325",
          "CVE-2026-70327",
          "CVE-2026-70328"
        ],
        "details": [
          {
            "id": "CVE-2026-58651",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33695,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62842",
            "title": "Microsoft Office Graphics Component Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0036,
            "epssPercentile": 0.29099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63513",
            "title": "Microsoft Office Graphics Component Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00352,
            "epssPercentile": 0.28156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63515",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00352,
            "epssPercentile": 0.28156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63517",
            "title": "Microsoft Office Graphics Component Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0036,
            "epssPercentile": 0.29099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63518",
            "title": "Microsoft Office Word Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00352,
            "epssPercentile": 0.28155,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63519",
            "title": "Microsoft Office Graphics Component Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00352,
            "epssPercentile": 0.28156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63524",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.2742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63526",
            "title": "Microsoft Office Graphics Component Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26935,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63527",
            "title": "Microsoft Office Word Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22641,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63528",
            "title": "Microsoft Office Word Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.27419,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63530",
            "title": "Microsoft Office Word Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00459,
            "epssPercentile": 0.38326,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63531",
            "title": "Microsoft Office Word Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.2742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63532",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26935,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63533",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22639,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64898",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26934,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64899",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.27419,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64903",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26934,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64904",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.2264,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64905",
            "title": "Microsoft Office Word Remote Code Execution Vulnerability",
            "summary": "Buffer over-read in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22638,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64907",
            "title": "Microsoft Office Word Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26933,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64909",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26935,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64910",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26934,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64911",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26935,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64915",
            "title": "Microsoft Office Word Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22641,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64917",
            "title": "Microsoft Office Word Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.2742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65657",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00439,
            "epssPercentile": 0.36836,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65664",
            "title": "Microsoft Office Graphics Component Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00352,
            "epssPercentile": 0.28155,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65807",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00442,
            "epssPercentile": 0.37048,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66807",
            "title": "Microsoft Office Graphics Component Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00352,
            "epssPercentile": 0.28155,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66809",
            "title": "Microsoft Office Graphics Component Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00277,
            "epssPercentile": 0.19871,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66810",
            "title": "Microsoft Office Word Information Disclosure Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00277,
            "epssPercentile": 0.1987,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68793",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25182,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68794",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00352,
            "epssPercentile": 0.28156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68795",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25183,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68796",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25182,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68797",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00447,
            "epssPercentile": 0.37485,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68798",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00421,
            "epssPercentile": 0.35358,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68799",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.27419,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68800",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25183,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68801",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25183,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68802",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.27418,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68803",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22639,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68804",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00352,
            "epssPercentile": 0.28155,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68805",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25181,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68806",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds write in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00393,
            "epssPercentile": 0.32536,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68807",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.2264,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68808",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.27421,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68810",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22642,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68811",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22639,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68812",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33695,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68813",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.2742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68814",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33696,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68815",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22642,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68816",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26934,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68817",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33696,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70310",
            "title": "Microsoft Word Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00277,
            "epssPercentile": 0.19871,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70311",
            "title": "Microsoft Office Word Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22638,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70312",
            "title": "Powerpoint Information Disclosure Vulnerability",
            "summary": "Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00277,
            "epssPercentile": 0.1987,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70313",
            "title": "Microsoft PowerPoint Remote Code Execution Vulnerability",
            "summary": "Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25182,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70314",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00467,
            "epssPercentile": 0.38833,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70315",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00375,
            "epssPercentile": 0.30683,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70316",
            "title": "Powerpoint Information Disclosure Vulnerability",
            "summary": "Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00375,
            "epssPercentile": 0.30685,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70317",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29015,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70318",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0036,
            "epssPercentile": 0.29099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70319",
            "title": "Microsoft Office Word Information Disclosure Vulnerability",
            "summary": "Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00375,
            "epssPercentile": 0.30683,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70320",
            "title": "Powerpoint Information Disclosure Vulnerability",
            "summary": "Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00375,
            "epssPercentile": 0.30684,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70322",
            "title": "Powerpoint Information Disclosure Vulnerability",
            "summary": "Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00375,
            "epssPercentile": 0.30684,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70323",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00375,
            "epssPercentile": 0.30684,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70325",
            "title": "Powerpoint Information Disclosure Vulnerability",
            "summary": "Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00375,
            "epssPercentile": 0.30684,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70327",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00853,
            "epssPercentile": 0.55907,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70328",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00853,
            "epssPercentile": 0.55907,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-65807",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-microsoft-office-msrc-2026-08-microsoft-office-release-notes-microsoft-office-ltsc-for-mac-2021",
      "slug": "microsoft-2026-08-microsoft-office-msrc-2026-08-microsoft-office-release-notes-microsoft-office-ltsc-for-mac-2021",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-08-microsoft-office-release-notes",
      "title": "Deploy Microsoft Microsoft Office update for Microsoft Office LTSC for Mac 2021",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://go.microsoft.com/fwlink/p/?linkid=831049",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft Office LTSC for Mac 2021",
      "platform": "Microsoft Office",
      "release_version": "16.112.26081010",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 72 linked CVEs for Microsoft Office LTSC for Mac 2021.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 72,
        "ids": [
          "CVE-2026-58651",
          "CVE-2026-62842",
          "CVE-2026-63513",
          "CVE-2026-63515",
          "CVE-2026-63517",
          "CVE-2026-63518",
          "CVE-2026-63519",
          "CVE-2026-63524",
          "CVE-2026-63526",
          "CVE-2026-63527",
          "CVE-2026-63528",
          "CVE-2026-63530",
          "CVE-2026-63531",
          "CVE-2026-63532",
          "CVE-2026-63533",
          "CVE-2026-64898",
          "CVE-2026-64899",
          "CVE-2026-64903",
          "CVE-2026-64904",
          "CVE-2026-64905",
          "CVE-2026-64907",
          "CVE-2026-64909",
          "CVE-2026-64910",
          "CVE-2026-64911",
          "CVE-2026-64915",
          "CVE-2026-64917",
          "CVE-2026-65657",
          "CVE-2026-65664",
          "CVE-2026-65807",
          "CVE-2026-66807",
          "CVE-2026-66809",
          "CVE-2026-66810",
          "CVE-2026-68793",
          "CVE-2026-68794",
          "CVE-2026-68795",
          "CVE-2026-68796",
          "CVE-2026-68797",
          "CVE-2026-68798",
          "CVE-2026-68799",
          "CVE-2026-68800",
          "CVE-2026-68801",
          "CVE-2026-68802",
          "CVE-2026-68803",
          "CVE-2026-68804",
          "CVE-2026-68805",
          "CVE-2026-68806",
          "CVE-2026-68807",
          "CVE-2026-68808",
          "CVE-2026-68810",
          "CVE-2026-68811",
          "CVE-2026-68812",
          "CVE-2026-68813",
          "CVE-2026-68814",
          "CVE-2026-68815",
          "CVE-2026-68816",
          "CVE-2026-68817",
          "CVE-2026-70310",
          "CVE-2026-70311",
          "CVE-2026-70312",
          "CVE-2026-70313",
          "CVE-2026-70314",
          "CVE-2026-70315",
          "CVE-2026-70316",
          "CVE-2026-70317",
          "CVE-2026-70318",
          "CVE-2026-70319",
          "CVE-2026-70320",
          "CVE-2026-70322",
          "CVE-2026-70323",
          "CVE-2026-70325",
          "CVE-2026-70327",
          "CVE-2026-70328"
        ],
        "details": [
          {
            "id": "CVE-2026-58651",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33695,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62842",
            "title": "Microsoft Office Graphics Component Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0036,
            "epssPercentile": 0.29099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63513",
            "title": "Microsoft Office Graphics Component Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00352,
            "epssPercentile": 0.28156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63515",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00352,
            "epssPercentile": 0.28156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63517",
            "title": "Microsoft Office Graphics Component Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0036,
            "epssPercentile": 0.29099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63518",
            "title": "Microsoft Office Word Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00352,
            "epssPercentile": 0.28155,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63519",
            "title": "Microsoft Office Graphics Component Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00352,
            "epssPercentile": 0.28156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63524",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.2742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63526",
            "title": "Microsoft Office Graphics Component Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26935,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63527",
            "title": "Microsoft Office Word Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22641,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63528",
            "title": "Microsoft Office Word Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.27419,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63530",
            "title": "Microsoft Office Word Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00459,
            "epssPercentile": 0.38326,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63531",
            "title": "Microsoft Office Word Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.2742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63532",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26935,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63533",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22639,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64898",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26934,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64899",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.27419,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64903",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26934,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64904",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.2264,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64905",
            "title": "Microsoft Office Word Remote Code Execution Vulnerability",
            "summary": "Buffer over-read in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22638,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64907",
            "title": "Microsoft Office Word Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26933,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64909",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26935,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64910",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26934,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64911",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26935,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64915",
            "title": "Microsoft Office Word Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22641,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64917",
            "title": "Microsoft Office Word Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.2742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65657",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00439,
            "epssPercentile": 0.36836,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65664",
            "title": "Microsoft Office Graphics Component Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00352,
            "epssPercentile": 0.28155,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65807",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00442,
            "epssPercentile": 0.37048,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66807",
            "title": "Microsoft Office Graphics Component Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00352,
            "epssPercentile": 0.28155,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66809",
            "title": "Microsoft Office Graphics Component Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00277,
            "epssPercentile": 0.19871,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66810",
            "title": "Microsoft Office Word Information Disclosure Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00277,
            "epssPercentile": 0.1987,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68793",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25182,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68794",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00352,
            "epssPercentile": 0.28156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68795",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25183,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68796",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25182,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68797",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00447,
            "epssPercentile": 0.37485,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68798",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00421,
            "epssPercentile": 0.35358,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68799",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.27419,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68800",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25183,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68801",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25183,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68802",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.27418,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68803",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22639,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68804",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00352,
            "epssPercentile": 0.28155,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68805",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25181,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68806",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds write in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00393,
            "epssPercentile": 0.32536,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68807",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.2264,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68808",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.27421,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68810",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22642,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68811",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22639,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68812",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33695,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68813",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.2742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68814",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33696,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68815",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22642,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68816",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26934,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68817",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33696,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70310",
            "title": "Microsoft Word Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00277,
            "epssPercentile": 0.19871,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70311",
            "title": "Microsoft Office Word Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22638,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70312",
            "title": "Powerpoint Information Disclosure Vulnerability",
            "summary": "Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00277,
            "epssPercentile": 0.1987,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70313",
            "title": "Microsoft PowerPoint Remote Code Execution Vulnerability",
            "summary": "Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25182,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70314",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00467,
            "epssPercentile": 0.38833,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70315",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00375,
            "epssPercentile": 0.30683,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70316",
            "title": "Powerpoint Information Disclosure Vulnerability",
            "summary": "Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00375,
            "epssPercentile": 0.30685,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70317",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29015,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70318",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0036,
            "epssPercentile": 0.29099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70319",
            "title": "Microsoft Office Word Information Disclosure Vulnerability",
            "summary": "Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00375,
            "epssPercentile": 0.30683,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70320",
            "title": "Powerpoint Information Disclosure Vulnerability",
            "summary": "Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00375,
            "epssPercentile": 0.30684,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70322",
            "title": "Powerpoint Information Disclosure Vulnerability",
            "summary": "Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00375,
            "epssPercentile": 0.30684,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70323",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00375,
            "epssPercentile": 0.30684,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70325",
            "title": "Powerpoint Information Disclosure Vulnerability",
            "summary": "Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00375,
            "epssPercentile": 0.30684,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70327",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00853,
            "epssPercentile": 0.55907,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70328",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00853,
            "epssPercentile": 0.55907,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-65807",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-microsoft-office-msrc-2026-08-microsoft-office-release-notes-microsoft-office-ltsc-for-mac-2024",
      "slug": "microsoft-2026-08-microsoft-office-msrc-2026-08-microsoft-office-release-notes-microsoft-office-ltsc-for-mac-2024",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-08-microsoft-office-release-notes",
      "title": "Deploy Microsoft Microsoft Office update for Microsoft Office LTSC for Mac 2024",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://go.microsoft.com/fwlink/p/?linkid=831049",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft Office LTSC for Mac 2024",
      "platform": "Microsoft Office",
      "release_version": "16.112.26081010",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 72 linked CVEs for Microsoft Office LTSC for Mac 2024.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 72,
        "ids": [
          "CVE-2026-58651",
          "CVE-2026-62842",
          "CVE-2026-63513",
          "CVE-2026-63515",
          "CVE-2026-63517",
          "CVE-2026-63518",
          "CVE-2026-63519",
          "CVE-2026-63524",
          "CVE-2026-63526",
          "CVE-2026-63527",
          "CVE-2026-63528",
          "CVE-2026-63530",
          "CVE-2026-63531",
          "CVE-2026-63532",
          "CVE-2026-63533",
          "CVE-2026-64898",
          "CVE-2026-64899",
          "CVE-2026-64903",
          "CVE-2026-64904",
          "CVE-2026-64905",
          "CVE-2026-64907",
          "CVE-2026-64909",
          "CVE-2026-64910",
          "CVE-2026-64911",
          "CVE-2026-64915",
          "CVE-2026-64917",
          "CVE-2026-65657",
          "CVE-2026-65664",
          "CVE-2026-65807",
          "CVE-2026-66807",
          "CVE-2026-66809",
          "CVE-2026-66810",
          "CVE-2026-68793",
          "CVE-2026-68794",
          "CVE-2026-68795",
          "CVE-2026-68796",
          "CVE-2026-68797",
          "CVE-2026-68798",
          "CVE-2026-68799",
          "CVE-2026-68800",
          "CVE-2026-68801",
          "CVE-2026-68802",
          "CVE-2026-68803",
          "CVE-2026-68804",
          "CVE-2026-68805",
          "CVE-2026-68806",
          "CVE-2026-68807",
          "CVE-2026-68808",
          "CVE-2026-68810",
          "CVE-2026-68811",
          "CVE-2026-68812",
          "CVE-2026-68813",
          "CVE-2026-68814",
          "CVE-2026-68815",
          "CVE-2026-68816",
          "CVE-2026-68817",
          "CVE-2026-70310",
          "CVE-2026-70311",
          "CVE-2026-70312",
          "CVE-2026-70313",
          "CVE-2026-70314",
          "CVE-2026-70315",
          "CVE-2026-70316",
          "CVE-2026-70317",
          "CVE-2026-70318",
          "CVE-2026-70319",
          "CVE-2026-70320",
          "CVE-2026-70322",
          "CVE-2026-70323",
          "CVE-2026-70325",
          "CVE-2026-70327",
          "CVE-2026-70328"
        ],
        "details": [
          {
            "id": "CVE-2026-58651",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33695,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62842",
            "title": "Microsoft Office Graphics Component Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0036,
            "epssPercentile": 0.29099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63513",
            "title": "Microsoft Office Graphics Component Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00352,
            "epssPercentile": 0.28156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63515",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00352,
            "epssPercentile": 0.28156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63517",
            "title": "Microsoft Office Graphics Component Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0036,
            "epssPercentile": 0.29099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63518",
            "title": "Microsoft Office Word Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00352,
            "epssPercentile": 0.28155,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63519",
            "title": "Microsoft Office Graphics Component Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00352,
            "epssPercentile": 0.28156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63524",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.2742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63526",
            "title": "Microsoft Office Graphics Component Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26935,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63527",
            "title": "Microsoft Office Word Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22641,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63528",
            "title": "Microsoft Office Word Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.27419,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63530",
            "title": "Microsoft Office Word Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00459,
            "epssPercentile": 0.38326,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63531",
            "title": "Microsoft Office Word Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.2742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63532",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26935,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-63533",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22639,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64898",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26934,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64899",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.27419,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64903",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26934,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64904",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.2264,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64905",
            "title": "Microsoft Office Word Remote Code Execution Vulnerability",
            "summary": "Buffer over-read in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22638,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64907",
            "title": "Microsoft Office Word Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26933,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64909",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26935,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64910",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26934,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64911",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26935,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64915",
            "title": "Microsoft Office Word Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22641,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-64917",
            "title": "Microsoft Office Word Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.2742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65657",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00439,
            "epssPercentile": 0.36836,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65664",
            "title": "Microsoft Office Graphics Component Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00352,
            "epssPercentile": 0.28155,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65807",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00442,
            "epssPercentile": 0.37048,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66807",
            "title": "Microsoft Office Graphics Component Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00352,
            "epssPercentile": 0.28155,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66809",
            "title": "Microsoft Office Graphics Component Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00277,
            "epssPercentile": 0.19871,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66810",
            "title": "Microsoft Office Word Information Disclosure Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00277,
            "epssPercentile": 0.1987,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68793",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25182,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68794",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00352,
            "epssPercentile": 0.28156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68795",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25183,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68796",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25182,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68797",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00447,
            "epssPercentile": 0.37485,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68798",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00421,
            "epssPercentile": 0.35358,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68799",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.27419,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68800",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25183,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68801",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25183,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68802",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.27418,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68803",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22639,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68804",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00352,
            "epssPercentile": 0.28155,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68805",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25181,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68806",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds write in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00393,
            "epssPercentile": 0.32536,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68807",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.2264,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68808",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.27421,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68810",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22642,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68811",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22639,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68812",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33695,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68813",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00345,
            "epssPercentile": 0.2742,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68814",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33696,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68815",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22642,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68816",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0034,
            "epssPercentile": 0.26934,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68817",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33696,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70310",
            "title": "Microsoft Word Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00277,
            "epssPercentile": 0.19871,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70311",
            "title": "Microsoft Office Word Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00303,
            "epssPercentile": 0.22638,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70312",
            "title": "Powerpoint Information Disclosure Vulnerability",
            "summary": "Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00277,
            "epssPercentile": 0.1987,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70313",
            "title": "Microsoft PowerPoint Remote Code Execution Vulnerability",
            "summary": "Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25182,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70314",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00467,
            "epssPercentile": 0.38833,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70315",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00375,
            "epssPercentile": 0.30683,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70316",
            "title": "Powerpoint Information Disclosure Vulnerability",
            "summary": "Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00375,
            "epssPercentile": 0.30685,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70317",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00359,
            "epssPercentile": 0.29015,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70318",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0036,
            "epssPercentile": 0.29099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70319",
            "title": "Microsoft Office Word Information Disclosure Vulnerability",
            "summary": "Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00375,
            "epssPercentile": 0.30683,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70320",
            "title": "Powerpoint Information Disclosure Vulnerability",
            "summary": "Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00375,
            "epssPercentile": 0.30684,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70322",
            "title": "Powerpoint Information Disclosure Vulnerability",
            "summary": "Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00375,
            "epssPercentile": 0.30684,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70323",
            "title": "Microsoft Office Information Disclosure Vulnerability",
            "summary": "Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00375,
            "epssPercentile": 0.30684,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70325",
            "title": "Powerpoint Information Disclosure Vulnerability",
            "summary": "Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00375,
            "epssPercentile": 0.30684,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70327",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00853,
            "epssPercentile": 0.55907,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70328",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00853,
            "epssPercentile": 0.55907,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-65807",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-microsoft-office-msrc-2026-08-microsoft-office-release-notes-onedrive-for-macos",
      "slug": "microsoft-2026-08-microsoft-office-msrc-2026-08-microsoft-office-release-notes-onedrive-for-macos",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-08-microsoft-office-release-notes",
      "title": "Deploy Microsoft Microsoft Office update for OneDrive for MacOS",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://oneclient.sfx.ms/Mac/Installers/26.095.0519.0003/universal/OneDrive.pkg",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "OneDrive for MacOS",
      "platform": "Microsoft Office",
      "release_version": "26.095.0519.0003",
      "action_type": "deploy-patch",
      "restart_required": "no",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for OneDrive for MacOS.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-65680"
        ],
        "details": [
          {
            "id": "CVE-2026-65680",
            "title": "Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00284,
            "epssPercentile": 0.20603,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 6.7,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-65680",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "The reviewed source does not require a restart.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-microsoft-office-msrc-2026-08-microsoft-office-release-notes-microsoft-teams-for-android",
      "slug": "microsoft-2026-08-microsoft-office-msrc-2026-08-microsoft-office-release-notes-microsoft-teams-for-android",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-08-microsoft-office-release-notes",
      "title": "Deploy Microsoft Microsoft Office update for Microsoft Teams for Android",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://play.google.com/store/apps/details?id=com.microsoft.teams",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft Teams for Android",
      "platform": "Microsoft Office",
      "release_version": "1.0.0.2026133602, 1.0.0.2026142702",
      "action_type": "deploy-patch",
      "restart_required": "no",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Microsoft Teams for Android.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 2,
        "ids": [
          "CVE-2026-65767",
          "CVE-2026-65768"
        ],
        "details": [
          {
            "id": "CVE-2026-65767",
            "title": "Microsoft Teams for Android Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00454,
            "epssPercentile": 0.3795,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65768",
            "title": "Microsoft Teams Remote Code Execution Vulnerability",
            "summary": "Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00625,
            "epssPercentile": 0.47747,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-65768",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "The reviewed source does not require a restart.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-microsoft-office-msrc-2026-08-microsoft-office-release-notes-microsoft-teams-for-ios",
      "slug": "microsoft-2026-08-microsoft-office-msrc-2026-08-microsoft-office-release-notes-microsoft-teams-for-ios",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-08-microsoft-office-release-notes",
      "title": "Deploy Microsoft Microsoft Office update for Microsoft Teams for iOS",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://apps.apple.com/us/app/microsoft-teams/id1113153706",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft Teams for iOS",
      "platform": "Microsoft Office",
      "release_version": "8.14.1",
      "action_type": "deploy-patch",
      "restart_required": "no",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Teams for iOS.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-65769"
        ],
        "details": [
          {
            "id": "CVE-2026-65769",
            "title": "Microsoft Teams iOS Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00661,
            "epssPercentile": 0.49338,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 6.5,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-65769",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "The reviewed source does not require a restart.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-open-source-software-msrc-2026-08-open-source-software-release-notes-azure-storage-explorer",
      "slug": "microsoft-2026-08-open-source-software-msrc-2026-08-open-source-software-release-notes-azure-storage-explorer",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-08-open-source-software-release-notes",
      "title": "Deploy Microsoft Open Source Software update for Azure Storage Explorer",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://github.com/microsoft/AzureStorageExplorer/releases/tag/v1.45.0",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Azure Storage Explorer",
      "platform": "Open Source Software",
      "release_version": "1.45.0",
      "action_type": "deploy-patch",
      "restart_required": "no",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Storage Explorer.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-57104"
        ],
        "details": [
          {
            "id": "CVE-2026-57104",
            "title": "Azure Storage Explorer Elevation of Privilege Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00808,
            "epssPercentile": 0.54489,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-57104",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "The reviewed source does not require a restart.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-other-msrc-2026-08-other-cbl-mariner-releases-21698-17084",
      "slug": "microsoft-2026-08-other-msrc-2026-08-other-cbl-mariner-releases-21698-17084",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-08-other-cbl-mariner-releases",
      "title": "Deploy Microsoft Other update for 21698-17084",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://msrc.microsoft.com/update-guide/releaseNote/2026-Aug",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "21698-17084",
      "platform": "Other",
      "release_version": "2.8.3-1",
      "action_type": "deploy-patch",
      "restart_required": "no",
      "vendor_severity": "Moderate",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for 21698-17084.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-72522"
        ],
        "details": [
          {
            "id": "CVE-2026-72522",
            "title": "libexpat project libexpat: Out-of-bounds Read",
            "summary": "libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00194,
            "epssPercentile": 0.09124,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 6.2,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-72522",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "The reviewed source does not require a restart.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-sql-server-msrc-2026-08-sql-server-release-notes-power-bi-report-server",
      "slug": "microsoft-2026-08-sql-server-msrc-2026-08-sql-server-release-notes-power-bi-report-server",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-08-sql-server-release-notes",
      "title": "Deploy Microsoft SQL Server update for Power BI Report Server",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://www.microsoft.com/en-us/download/details.aspx?id=105944",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Power BI Report Server",
      "platform": "SQL Server",
      "release_version": "1.26.9682.1442",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Power BI Report Server.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-65811"
        ],
        "details": [
          {
            "id": "CVE-2026-65811",
            "title": "Power BI Remote Code Execution Vulnerability",
            "summary": "Improper input validation in Power BI allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00525,
            "epssPercentile": 0.42634,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-65811",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-server-software-kb5121573",
      "slug": "microsoft-2026-08-server-software-kb5121573",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5121573",
      "title": "Deploy Microsoft Server Software security update KB5121573",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5121573",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft Exchange Server Subscription Edition RTM",
      "platform": "Server Software",
      "release_version": "15.02.2562.046",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 7 linked CVEs for Microsoft Exchange Server Subscription Edition RTM.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 7,
        "ids": [
          "CVE-2026-62910",
          "CVE-2026-62911",
          "CVE-2026-62912",
          "CVE-2026-62913",
          "CVE-2026-62914",
          "CVE-2026-62915",
          "CVE-2026-65813"
        ],
        "details": [
          {
            "id": "CVE-2026-62910",
            "title": "Microsoft Exchange Server Elevation of Privilege Vulnerability",
            "summary": "Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.",
            "score": 7.2,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00678,
            "epssPercentile": 0.50038,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62911",
            "title": "Microsoft Exchange Server Elevation of Privilege Vulnerability",
            "summary": "Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "CISA Vulnrichment records proof-of-concept exploitation in its SSVC data. BlackTree has not independently executed or validated exploit material.",
            "epss": 0.01324,
            "epssPercentile": 0.69056,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62912",
            "title": "Microsoft Exchange Server Denial of Service Vulnerability",
            "summary": "Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01315,
            "epssPercentile": 0.68862,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62913",
            "title": "Microsoft Exchange Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00652,
            "epssPercentile": 0.48971,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62914",
            "title": "Microsoft Exchange Server Spoofing Vulnerability",
            "summary": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00335,
            "epssPercentile": 0.26317,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62915",
            "title": "Microsoft Exchange Server Security Feature Bypass Vulnerability",
            "summary": "Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00484,
            "epssPercentile": 0.39964,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65813",
            "title": "Microsoft Exchange Server Elevation of Privilege Vulnerability",
            "summary": "Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0065,
            "epssPercentile": 0.48868,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-62913",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-system-center-msrc-2026-08-system-center-release-notes-microsoft-defender-for-endpoint-for-mac",
      "slug": "microsoft-2026-08-system-center-msrc-2026-08-system-center-release-notes-microsoft-defender-for-endpoint-for-mac",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-08-system-center-release-notes",
      "title": "Deploy Microsoft System Center update for Microsoft Defender for Endpoint for Mac",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://msrc.microsoft.com/update-guide/releaseNote/2026-Aug",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Microsoft Defender for Endpoint for Mac",
      "platform": "System Center",
      "release_version": "101.26042.0020",
      "action_type": "deploy-patch",
      "restart_required": "no",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Defender for Endpoint for Mac.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-54123"
        ],
        "details": [
          {
            "id": "CVE-2026-54123",
            "title": "Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00438,
            "epssPercentile": 0.36751,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 5.5,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-54123",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "The reviewed source does not require a restart.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-windows-kb5120228",
      "slug": "microsoft-2026-08-windows-kb5120228",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5120228",
      "title": "Deploy Microsoft Windows security update KB5120228",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5120228",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Windows Server 2025, Windows Server 2025 (Server Core installation)",
      "platform": "Windows",
      "release_version": "10.0.26100.33222",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 215 linked CVEs for Windows Server 2025, Windows Server 2025 (Server Core installation). Microsoft reports exploitation for CVE-2026-68820.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 215,
        "ids": [
          "CVE-2026-42976",
          "CVE-2026-49179",
          "CVE-2026-50472",
          "CVE-2026-54113",
          "CVE-2026-54984",
          "CVE-2026-56174",
          "CVE-2026-56179",
          "CVE-2026-59122",
          "CVE-2026-59125",
          "CVE-2026-59126",
          "CVE-2026-59127",
          "CVE-2026-59128",
          "CVE-2026-59130",
          "CVE-2026-59131",
          "CVE-2026-59132",
          "CVE-2026-59134",
          "CVE-2026-59135",
          "CVE-2026-59136",
          "CVE-2026-59137",
          "CVE-2026-59138",
          "CVE-2026-61345",
          "CVE-2026-61346",
          "CVE-2026-61347",
          "CVE-2026-61348",
          "CVE-2026-61349",
          "CVE-2026-61350",
          "CVE-2026-61352",
          "CVE-2026-61353",
          "CVE-2026-61355",
          "CVE-2026-61356",
          "CVE-2026-61357",
          "CVE-2026-61358",
          "CVE-2026-61359",
          "CVE-2026-61360",
          "CVE-2026-61361",
          "CVE-2026-61363",
          "CVE-2026-61364",
          "CVE-2026-61365",
          "CVE-2026-61366",
          "CVE-2026-61367",
          "CVE-2026-61368",
          "CVE-2026-61918",
          "CVE-2026-61920",
          "CVE-2026-61921",
          "CVE-2026-61923",
          "CVE-2026-61924",
          "CVE-2026-61925",
          "CVE-2026-61926",
          "CVE-2026-61927",
          "CVE-2026-61928",
          "CVE-2026-61929",
          "CVE-2026-61930",
          "CVE-2026-61933",
          "CVE-2026-61934",
          "CVE-2026-61936",
          "CVE-2026-61937",
          "CVE-2026-61938",
          "CVE-2026-61939",
          "CVE-2026-62690",
          "CVE-2026-62692",
          "CVE-2026-62695",
          "CVE-2026-62696",
          "CVE-2026-62698",
          "CVE-2026-62699",
          "CVE-2026-62700",
          "CVE-2026-62701",
          "CVE-2026-62702",
          "CVE-2026-62703",
          "CVE-2026-62707",
          "CVE-2026-62708",
          "CVE-2026-62709",
          "CVE-2026-62710",
          "CVE-2026-62711",
          "CVE-2026-62712",
          "CVE-2026-62713",
          "CVE-2026-62714",
          "CVE-2026-62715",
          "CVE-2026-62716",
          "CVE-2026-62717",
          "CVE-2026-62718",
          "CVE-2026-62719",
          "CVE-2026-62720",
          "CVE-2026-62721",
          "CVE-2026-62722",
          "CVE-2026-62723",
          "CVE-2026-62724",
          "CVE-2026-62725",
          "CVE-2026-62726",
          "CVE-2026-62727",
          "CVE-2026-62728",
          "CVE-2026-62729",
          "CVE-2026-62730",
          "CVE-2026-62732",
          "CVE-2026-62733",
          "CVE-2026-62734",
          "CVE-2026-62735",
          "CVE-2026-62736",
          "CVE-2026-62737",
          "CVE-2026-62738",
          "CVE-2026-62739",
          "CVE-2026-62740",
          "CVE-2026-62741",
          "CVE-2026-62742",
          "CVE-2026-62743",
          "CVE-2026-62745",
          "CVE-2026-62746",
          "CVE-2026-62747",
          "CVE-2026-62748",
          "CVE-2026-62749",
          "CVE-2026-62750",
          "CVE-2026-62751",
          "CVE-2026-62752",
          "CVE-2026-62753",
          "CVE-2026-62754",
          "CVE-2026-62755",
          "CVE-2026-62757",
          "CVE-2026-62758",
          "CVE-2026-62761",
          "CVE-2026-62766",
          "CVE-2026-62768",
          "CVE-2026-62769",
          "CVE-2026-62770",
          "CVE-2026-62771",
          "CVE-2026-62773",
          "CVE-2026-62774",
          "CVE-2026-62776",
          "CVE-2026-62777",
          "CVE-2026-62778",
          "CVE-2026-62779",
          "CVE-2026-62780",
          "CVE-2026-62781",
          "CVE-2026-62782",
          "CVE-2026-62783",
          "CVE-2026-62784",
          "CVE-2026-62785",
          "CVE-2026-62786",
          "CVE-2026-62787",
          "CVE-2026-62788",
          "CVE-2026-62790",
          "CVE-2026-62792",
          "CVE-2026-62793",
          "CVE-2026-62795",
          "CVE-2026-62796",
          "CVE-2026-62797",
          "CVE-2026-62798",
          "CVE-2026-62800",
          "CVE-2026-62803",
          "CVE-2026-62807",
          "CVE-2026-62811",
          "CVE-2026-62812",
          "CVE-2026-62814",
          "CVE-2026-62815",
          "CVE-2026-62816",
          "CVE-2026-62817",
          "CVE-2026-62818",
          "CVE-2026-62819",
          "CVE-2026-62820",
          "CVE-2026-62822",
          "CVE-2026-62823",
          "CVE-2026-62832",
          "CVE-2026-62876",
          "CVE-2026-62877",
          "CVE-2026-62878",
          "CVE-2026-62880",
          "CVE-2026-62881",
          "CVE-2026-62883",
          "CVE-2026-62885",
          "CVE-2026-62887",
          "CVE-2026-62888",
          "CVE-2026-62889",
          "CVE-2026-62890",
          "CVE-2026-62892",
          "CVE-2026-62893",
          "CVE-2026-62894",
          "CVE-2026-62908",
          "CVE-2026-65662",
          "CVE-2026-65671",
          "CVE-2026-65672",
          "CVE-2026-65678",
          "CVE-2026-65679",
          "CVE-2026-65681",
          "CVE-2026-65773",
          "CVE-2026-65774",
          "CVE-2026-65775",
          "CVE-2026-65776",
          "CVE-2026-65777",
          "CVE-2026-65784",
          "CVE-2026-65785",
          "CVE-2026-65786",
          "CVE-2026-65787",
          "CVE-2026-65788",
          "CVE-2026-65789",
          "CVE-2026-65790",
          "CVE-2026-65791",
          "CVE-2026-65794",
          "CVE-2026-65795",
          "CVE-2026-65796",
          "CVE-2026-65797",
          "CVE-2026-65798",
          "CVE-2026-65799",
          "CVE-2026-65814",
          "CVE-2026-66799",
          "CVE-2026-66802",
          "CVE-2026-6726",
          "CVE-2026-6727",
          "CVE-2026-68819",
          "CVE-2026-68820",
          "CVE-2026-70304",
          "CVE-2026-70307",
          "CVE-2026-70330",
          "CVE-2026-70344",
          "CVE-2026-70345",
          "CVE-2026-70346",
          "CVE-2026-70347",
          "CVE-2026-71331"
        ],
        "details": [
          {
            "id": "CVE-2026-42976",
            "title": "Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11772,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49179",
            "title": "Windows Active Directory Domain Services Remote Code Execution Vulnerability",
            "summary": "Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00831,
            "epssPercentile": 0.55217,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50472",
            "title": "Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54113",
            "title": "Remote Procedure Call Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01126,
            "epssPercentile": 0.64162,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54984",
            "title": "Windows Imaging Component Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.006,
            "epssPercentile": 0.46535,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56174",
            "title": "Windows Narrator Braille Elevation of Privilege Vulnerability",
            "summary": "Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00291,
            "epssPercentile": 0.21293,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56179",
            "title": "Windows Network Address Translation (NAT) Spoofing Vulnerability",
            "summary": "Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.",
            "score": 8.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00234,
            "epssPercentile": 0.14223,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59122",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59125",
            "title": "Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability",
            "summary": "Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59126",
            "title": "Windows Event Logging Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59127",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23557,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59128",
            "title": "Windows Encrypting File System (EFS) Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31953,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59130",
            "title": "AMD Zen Information Disclosure Vulnerability",
            "summary": "No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00337,
            "epssPercentile": 0.26512,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59131",
            "title": "AMD Zen Information Disclosure Vulnerability",
            "summary": "No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00284,
            "epssPercentile": 0.20673,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59132",
            "title": "Windows TCP/IP Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01686,
            "epssPercentile": 0.75496,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59134",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00624,
            "epssPercentile": 0.47693,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59135",
            "title": "Microsoft Windows Search Component Information Disclosure Vulnerability",
            "summary": "Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0032,
            "epssPercentile": 0.24552,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59136",
            "title": "Microsoft COM for Windows Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0037,
            "epssPercentile": 0.30138,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59137",
            "title": "Windows Event Logging Service Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31953,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59138",
            "title": "Microsoft Remote Registry Service Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01042,
            "epssPercentile": 0.61833,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61345",
            "title": "Microsoft Remote Registry Service Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01042,
            "epssPercentile": 0.61834,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61346",
            "title": "Windows Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61347",
            "title": "Windows Event Logging Service Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61348",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0159,
            "epssPercentile": 0.7403,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61349",
            "title": "Windows Work Folder Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00238,
            "epssPercentile": 0.14813,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61350",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00449,
            "epssPercentile": 0.3762,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61352",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00428,
            "epssPercentile": 0.35876,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61353",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61355",
            "title": "Windows Sensor Data Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23556,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61356",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61357",
            "title": "Application Information Services Elevation of Privilege Vulnerability",
            "summary": "Use after free in Application Information Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23556,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61358",
            "title": "Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0368,
            "epssPercentile": 0.88942,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61359",
            "title": "Windows Storage Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00334,
            "epssPercentile": 0.26154,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61360",
            "title": "Windows GDI Information Disclosure Vulnerability",
            "summary": "Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31956,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61361",
            "title": "Windows DHCP Client Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows DHCP Client allows an authorized attacker to execute code locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61363",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00625,
            "epssPercentile": 0.47727,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61364",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61365",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61366",
            "title": "Windows Network Connection Broker Elevation of Privilege Vulnerability",
            "summary": "Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61367",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61368",
            "title": "Windows Hyper-V Information Disclosure Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally.",
            "score": 5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00372,
            "epssPercentile": 0.30393,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61918",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00869,
            "epssPercentile": 0.56428,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61920",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a network.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00484,
            "epssPercentile": 0.39993,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61921",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00829,
            "epssPercentile": 0.55174,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61923",
            "title": "Windows Display Enhancement Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61924",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00829,
            "epssPercentile": 0.55173,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61925",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00381,
            "epssPercentile": 0.31232,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61926",
            "title": "Windows USB Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61927",
            "title": "Windows Bind Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08564,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61928",
            "title": "Windows Hello Tampering Vulnerability",
            "summary": "Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0021,
            "epssPercentile": 0.11257,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61929",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01676,
            "epssPercentile": 0.75331,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61930",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02092,
            "epssPercentile": 0.80405,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61933",
            "title": "Windows DWM Core Library Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61934",
            "title": "Windows Bind Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61936",
            "title": "Windows Defender Firewall Service Security Feature Bypass Vulnerability",
            "summary": "Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00282,
            "epssPercentile": 0.20397,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61937",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61938",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61939",
            "title": "Winlogon Elevation of Privilege Vulnerability",
            "summary": "Use after free in Winlogon allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15759,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62690",
            "title": "Windows Push Notifications Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62692",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62695",
            "title": "Windows Storage Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.2356,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62696",
            "title": "Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03401,
            "epssPercentile": 0.88059,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62698",
            "title": "Microsoft Digest Authentication Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00361,
            "epssPercentile": 0.29142,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62699",
            "title": "Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to execute code with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00409,
            "epssPercentile": 0.34136,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62700",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62701",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62702",
            "title": "Windows Graphics Kernel Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00943,
            "epssPercentile": 0.58737,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62703",
            "title": "Windows DWM Core Library Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31954,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62707",
            "title": "Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62708",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00316,
            "epssPercentile": 0.24162,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62709",
            "title": "Windows GDI+ Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31908,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62710",
            "title": "Windows Device Association Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62711",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23518,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62712",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0038,
            "epssPercentile": 0.31158,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62713",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0195,
            "epssPercentile": 0.78893,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62714",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00468,
            "epssPercentile": 0.3888,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62715",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0048,
            "epssPercentile": 0.3977,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62716",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00468,
            "epssPercentile": 0.3888,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62717",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62718",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0048,
            "epssPercentile": 0.39771,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62719",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62720",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00468,
            "epssPercentile": 0.3888,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62721",
            "title": "Windows User-Mode Power Service (UMPS) Elevation of Privilege Vulnerability",
            "summary": "Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0038,
            "epssPercentile": 0.31198,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62722",
            "title": "Microsoft Brokering File System Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Brokering File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62723",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62724",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15758,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62725",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09788,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62726",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15758,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62727",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00186,
            "epssPercentile": 0.08256,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62728",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62729",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62730",
            "title": "Windows Wired AutoConfig Service Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62732",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62733",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62734",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62735",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00476,
            "epssPercentile": 0.39473,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62736",
            "title": "Windows DHCP Client Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15004,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62737",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02844,
            "epssPercentile": 0.85765,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62738",
            "title": "Windows Management Instrumentation Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62739",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00249,
            "epssPercentile": 0.1616,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62740",
            "title": "Windows Imaging Component Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31908,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62741",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02092,
            "epssPercentile": 0.80405,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62742",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0048,
            "epssPercentile": 0.39771,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62743",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31954,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62745",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00361,
            "epssPercentile": 0.29156,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62746",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31954,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62747",
            "title": "Windows Device Association Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23557,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62748",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08564,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62749",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09786,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62750",
            "title": "Windows HTTP Protocol Stack Tampering Vulnerability",
            "summary": "Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00574,
            "epssPercentile": 0.45288,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62751",
            "title": "Windows Projected File System Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23557,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62752",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23556,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62753",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00207,
            "epssPercentile": 0.10799,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62754",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62755",
            "title": "Windows DHCP Client Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62757",
            "title": "Windows Schannel Security Feature Bypass Vulnerability",
            "summary": "Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00255,
            "epssPercentile": 0.16929,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62758",
            "title": "Windows Remote Access Connection Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.14966,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62761",
            "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00355,
            "epssPercentile": 0.28559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62766",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Double free in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01522,
            "epssPercentile": 0.72941,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62768",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62769",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62770",
            "title": "Windows Shell Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15007,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62771",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00249,
            "epssPercentile": 0.1616,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62773",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09787,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62774",
            "title": "Windows Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09787,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62776",
            "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00271,
            "epssPercentile": 0.19237,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62777",
            "title": "Windows License Manager Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11773,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62778",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00506,
            "epssPercentile": 0.41401,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62779",
            "title": "Windows Schannel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Schannel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62780",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10199,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62781",
            "title": "RPC Runtime Library Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00519,
            "epssPercentile": 0.42242,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62782",
            "title": "Windows SMB Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00868,
            "epssPercentile": 0.56396,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62783",
            "title": "Windows Remote Access Connection Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01951,
            "epssPercentile": 0.78901,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62784",
            "title": "Microsoft Local Security Authority Server (lsasrv) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00934,
            "epssPercentile": 0.58442,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62785",
            "title": "Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00837,
            "epssPercentile": 0.55424,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62786",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62787",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows DNS allows an authorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0053,
            "epssPercentile": 0.4292,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62788",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26033,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62790",
            "title": "Windows SMBv3 Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00664,
            "epssPercentile": 0.49429,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62792",
            "title": "Windows TCP/IP Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00708,
            "epssPercentile": 0.51162,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62793",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23712,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62795",
            "title": "Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00607,
            "epssPercentile": 0.46873,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62796",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62797",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00334,
            "epssPercentile": 0.26156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62798",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23712,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62800",
            "title": "Windows SMBv3 Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00934,
            "epssPercentile": 0.58442,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62803",
            "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00371,
            "epssPercentile": 0.30191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62807",
            "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00371,
            "epssPercentile": 0.30191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62811",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00334,
            "epssPercentile": 0.26156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62812",
            "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00291,
            "epssPercentile": 0.21362,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62814",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00537,
            "epssPercentile": 0.43342,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62815",
            "title": "Microsoft QUIC Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00982,
            "epssPercentile": 0.6,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62816",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00393,
            "epssPercentile": 0.32547,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62817",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00668,
            "epssPercentile": 0.49598,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62818",
            "title": "Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability",
            "summary": "Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00972,
            "epssPercentile": 0.59701,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62819",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00579,
            "epssPercentile": 0.45525,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62820",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00543,
            "epssPercentile": 0.43643,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62822",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00633,
            "epssPercentile": 0.48082,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62823",
            "title": "Windows DHCP Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00662,
            "epssPercentile": 0.49371,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62832",
            "title": "Windows User Profile Service Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03295,
            "epssPercentile": 0.87687,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62876",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62877",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62878",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0126,
            "epssPercentile": 0.67668,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62880",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15004,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62881",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62883",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17628,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62885",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62887",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22166,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62888",
            "title": "Windows DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01951,
            "epssPercentile": 0.78901,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62889",
            "title": "Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability",
            "summary": "Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0056,
            "epssPercentile": 0.44552,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62890",
            "title": "Windows GDI+ Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00269,
            "epssPercentile": 0.18868,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62892",
            "title": "Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability",
            "summary": "Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09787,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62893",
            "title": "Windows Deployment Services TFTP Server Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02732,
            "epssPercentile": 0.85128,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62894",
            "title": "Windows DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00249,
            "epssPercentile": 0.16159,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62908",
            "title": "Windows Backup Engine Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00153,
            "epssPercentile": 0.04738,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65662",
            "title": "Windows GDI Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65671",
            "title": "Remote Access API Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00257,
            "epssPercentile": 0.17266,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65672",
            "title": "Remote Access API Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00257,
            "epssPercentile": 0.17267,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65678",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11662,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65679",
            "title": "Windows iSCSI Target Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00566,
            "epssPercentile": 0.44906,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65681",
            "title": "Windows iSCSI Target Service Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00886,
            "epssPercentile": 0.56926,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65773",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00242,
            "epssPercentile": 0.15314,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65774",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00257,
            "epssPercentile": 0.17266,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65775",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02609,
            "epssPercentile": 0.84381,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65776",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00225,
            "epssPercentile": 0.13105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65777",
            "title": "Active Directory Security Feature Bypass Vulnerability",
            "summary": "Inadequate encryption strength in Windows Active Directory allows an authorized attacker to bypass a security feature over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00288,
            "epssPercentile": 0.21003,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65784",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00299,
            "epssPercentile": 0.22201,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65785",
            "title": "Windows DHCP Client Denial of Service Vulnerability",
            "summary": "Uncontrolled resource consumption in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00378,
            "epssPercentile": 0.30924,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65786",
            "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65787",
            "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.2356,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65788",
            "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
            "summary": "Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01676,
            "epssPercentile": 0.75331,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65789",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00544,
            "epssPercentile": 0.43722,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65790",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15007,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65791",
            "title": "Windows iSCSI Target Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.006,
            "epssPercentile": 0.46555,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65794",
            "title": "Windows SMB Client Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00651,
            "epssPercentile": 0.48924,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65795",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17627,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65796",
            "title": "Windows iSCSI Target Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00528,
            "epssPercentile": 0.42787,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65797",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17582,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65798",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17628,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65799",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00253,
            "epssPercentile": 0.16631,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65814",
            "title": "Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00252,
            "epssPercentile": 0.16578,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66799",
            "title": "Windows Key Guard Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00269,
            "epssPercentile": 0.18868,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66802",
            "title": "Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0036,
            "epssPercentile": 0.29053,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-6726",
            "title": "An information leakage vulnerability in the TCG TPM 2.0 reference code.",
            "summary": "An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key. See also TCG VRT0010.",
            "score": 7.9,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00215,
            "epssPercentile": 0.11783,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-6727",
            "title": "CVE-2026-6727",
            "summary": "A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with access to the TPM command interface may be able to exploit timing differences to recover information that could allow decryption of ciphertexts encrypted to TPM-managed RSA keys, including the RSA Endorsement Key (EK), including import blobs, credential blobs, and session salts. Under certain conditi",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00203,
            "epssPercentile": 0.10248,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68819",
            "title": "Windows Network File System Denial of Service Vulnerability",
            "summary": "Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00684,
            "epssPercentile": 0.50268,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68820",
            "title": "Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability",
            "summary": "Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2026-08-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.06184,
            "epssPercentile": 0.93023,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2026-08-25 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70304",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00316,
            "epssPercentile": 0.24068,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70307",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00322,
            "epssPercentile": 0.24811,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70330",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00316,
            "epssPercentile": 0.24068,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70344",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70345",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70346",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70347",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23517,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-71331",
            "title": "Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00454,
            "epssPercentile": 0.37968,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Exploitation reported by the vendor source",
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-65791",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-windows-kb5120229",
      "slug": "microsoft-2026-08-windows-kb5120229",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5120229",
      "title": "Deploy Microsoft Windows security update KB5120229",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5120229",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Windows Server 2022, Windows Server 2022 (Server Core installation)",
      "platform": "Windows",
      "release_version": "10.0.20348.5440",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 195 linked CVEs for Windows Server 2022, Windows Server 2022 (Server Core installation). Microsoft reports exploitation for CVE-2026-68820.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 195,
        "ids": [
          "CVE-2026-42976",
          "CVE-2026-49179",
          "CVE-2026-50472",
          "CVE-2026-54113",
          "CVE-2026-54984",
          "CVE-2026-56174",
          "CVE-2026-59122",
          "CVE-2026-59125",
          "CVE-2026-59126",
          "CVE-2026-59127",
          "CVE-2026-59128",
          "CVE-2026-59130",
          "CVE-2026-59131",
          "CVE-2026-59132",
          "CVE-2026-59134",
          "CVE-2026-59135",
          "CVE-2026-59136",
          "CVE-2026-59137",
          "CVE-2026-59138",
          "CVE-2026-61345",
          "CVE-2026-61346",
          "CVE-2026-61347",
          "CVE-2026-61348",
          "CVE-2026-61349",
          "CVE-2026-61350",
          "CVE-2026-61352",
          "CVE-2026-61353",
          "CVE-2026-61355",
          "CVE-2026-61356",
          "CVE-2026-61358",
          "CVE-2026-61359",
          "CVE-2026-61360",
          "CVE-2026-61363",
          "CVE-2026-61364",
          "CVE-2026-61365",
          "CVE-2026-61366",
          "CVE-2026-61367",
          "CVE-2026-61368",
          "CVE-2026-61918",
          "CVE-2026-61920",
          "CVE-2026-61921",
          "CVE-2026-61923",
          "CVE-2026-61924",
          "CVE-2026-61925",
          "CVE-2026-61926",
          "CVE-2026-61928",
          "CVE-2026-61930",
          "CVE-2026-61932",
          "CVE-2026-61936",
          "CVE-2026-61937",
          "CVE-2026-61939",
          "CVE-2026-62690",
          "CVE-2026-62692",
          "CVE-2026-62695",
          "CVE-2026-62696",
          "CVE-2026-62698",
          "CVE-2026-62699",
          "CVE-2026-62700",
          "CVE-2026-62701",
          "CVE-2026-62702",
          "CVE-2026-62703",
          "CVE-2026-62707",
          "CVE-2026-62709",
          "CVE-2026-62710",
          "CVE-2026-62711",
          "CVE-2026-62712",
          "CVE-2026-62713",
          "CVE-2026-62714",
          "CVE-2026-62715",
          "CVE-2026-62716",
          "CVE-2026-62717",
          "CVE-2026-62718",
          "CVE-2026-62719",
          "CVE-2026-62720",
          "CVE-2026-62721",
          "CVE-2026-62723",
          "CVE-2026-62724",
          "CVE-2026-62725",
          "CVE-2026-62726",
          "CVE-2026-62727",
          "CVE-2026-62728",
          "CVE-2026-62729",
          "CVE-2026-62730",
          "CVE-2026-62732",
          "CVE-2026-62733",
          "CVE-2026-62734",
          "CVE-2026-62735",
          "CVE-2026-62738",
          "CVE-2026-62739",
          "CVE-2026-62740",
          "CVE-2026-62741",
          "CVE-2026-62742",
          "CVE-2026-62743",
          "CVE-2026-62745",
          "CVE-2026-62746",
          "CVE-2026-62747",
          "CVE-2026-62748",
          "CVE-2026-62750",
          "CVE-2026-62751",
          "CVE-2026-62752",
          "CVE-2026-62753",
          "CVE-2026-62754",
          "CVE-2026-62755",
          "CVE-2026-62757",
          "CVE-2026-62758",
          "CVE-2026-62761",
          "CVE-2026-62768",
          "CVE-2026-62769",
          "CVE-2026-62770",
          "CVE-2026-62771",
          "CVE-2026-62773",
          "CVE-2026-62774",
          "CVE-2026-62776",
          "CVE-2026-62777",
          "CVE-2026-62778",
          "CVE-2026-62781",
          "CVE-2026-62782",
          "CVE-2026-62783",
          "CVE-2026-62784",
          "CVE-2026-62785",
          "CVE-2026-62786",
          "CVE-2026-62787",
          "CVE-2026-62790",
          "CVE-2026-62792",
          "CVE-2026-62793",
          "CVE-2026-62795",
          "CVE-2026-62796",
          "CVE-2026-62797",
          "CVE-2026-62800",
          "CVE-2026-62803",
          "CVE-2026-62807",
          "CVE-2026-62811",
          "CVE-2026-62812",
          "CVE-2026-62814",
          "CVE-2026-62815",
          "CVE-2026-62816",
          "CVE-2026-62817",
          "CVE-2026-62818",
          "CVE-2026-62819",
          "CVE-2026-62820",
          "CVE-2026-62822",
          "CVE-2026-62823",
          "CVE-2026-62832",
          "CVE-2026-62876",
          "CVE-2026-62877",
          "CVE-2026-62878",
          "CVE-2026-62880",
          "CVE-2026-62881",
          "CVE-2026-62883",
          "CVE-2026-62885",
          "CVE-2026-62887",
          "CVE-2026-62888",
          "CVE-2026-62889",
          "CVE-2026-62890",
          "CVE-2026-62892",
          "CVE-2026-62893",
          "CVE-2026-62894",
          "CVE-2026-62908",
          "CVE-2026-65662",
          "CVE-2026-65671",
          "CVE-2026-65672",
          "CVE-2026-65678",
          "CVE-2026-65679",
          "CVE-2026-65681",
          "CVE-2026-65773",
          "CVE-2026-65774",
          "CVE-2026-65775",
          "CVE-2026-65777",
          "CVE-2026-65784",
          "CVE-2026-65786",
          "CVE-2026-65787",
          "CVE-2026-65789",
          "CVE-2026-65790",
          "CVE-2026-65791",
          "CVE-2026-65794",
          "CVE-2026-65795",
          "CVE-2026-65796",
          "CVE-2026-65797",
          "CVE-2026-65798",
          "CVE-2026-65799",
          "CVE-2026-65814",
          "CVE-2026-66799",
          "CVE-2026-66802",
          "CVE-2026-6726",
          "CVE-2026-6727",
          "CVE-2026-68819",
          "CVE-2026-68820",
          "CVE-2026-70304",
          "CVE-2026-70307",
          "CVE-2026-70330",
          "CVE-2026-70344",
          "CVE-2026-70345",
          "CVE-2026-70346",
          "CVE-2026-70347",
          "CVE-2026-71331"
        ],
        "details": [
          {
            "id": "CVE-2026-42976",
            "title": "Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11772,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49179",
            "title": "Windows Active Directory Domain Services Remote Code Execution Vulnerability",
            "summary": "Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00831,
            "epssPercentile": 0.55217,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50472",
            "title": "Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54113",
            "title": "Remote Procedure Call Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01126,
            "epssPercentile": 0.64162,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54984",
            "title": "Windows Imaging Component Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.006,
            "epssPercentile": 0.46535,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56174",
            "title": "Windows Narrator Braille Elevation of Privilege Vulnerability",
            "summary": "Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00291,
            "epssPercentile": 0.21293,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59122",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59125",
            "title": "Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability",
            "summary": "Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59126",
            "title": "Windows Event Logging Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59127",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23557,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59128",
            "title": "Windows Encrypting File System (EFS) Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31953,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59130",
            "title": "AMD Zen Information Disclosure Vulnerability",
            "summary": "No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00337,
            "epssPercentile": 0.26512,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59131",
            "title": "AMD Zen Information Disclosure Vulnerability",
            "summary": "No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00284,
            "epssPercentile": 0.20673,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59132",
            "title": "Windows TCP/IP Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01686,
            "epssPercentile": 0.75496,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59134",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00624,
            "epssPercentile": 0.47693,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59135",
            "title": "Microsoft Windows Search Component Information Disclosure Vulnerability",
            "summary": "Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0032,
            "epssPercentile": 0.24552,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59136",
            "title": "Microsoft COM for Windows Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0037,
            "epssPercentile": 0.30138,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59137",
            "title": "Windows Event Logging Service Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31953,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59138",
            "title": "Microsoft Remote Registry Service Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01042,
            "epssPercentile": 0.61833,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61345",
            "title": "Microsoft Remote Registry Service Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01042,
            "epssPercentile": 0.61834,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61346",
            "title": "Windows Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61347",
            "title": "Windows Event Logging Service Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61348",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0159,
            "epssPercentile": 0.7403,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61349",
            "title": "Windows Work Folder Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00238,
            "epssPercentile": 0.14813,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61350",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00449,
            "epssPercentile": 0.3762,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61352",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00428,
            "epssPercentile": 0.35876,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61353",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61355",
            "title": "Windows Sensor Data Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23556,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61356",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61358",
            "title": "Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0368,
            "epssPercentile": 0.88942,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61359",
            "title": "Windows Storage Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00334,
            "epssPercentile": 0.26154,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61360",
            "title": "Windows GDI Information Disclosure Vulnerability",
            "summary": "Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31956,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61363",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00625,
            "epssPercentile": 0.47727,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61364",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61365",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61366",
            "title": "Windows Network Connection Broker Elevation of Privilege Vulnerability",
            "summary": "Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61367",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61368",
            "title": "Windows Hyper-V Information Disclosure Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally.",
            "score": 5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00372,
            "epssPercentile": 0.30393,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61918",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00869,
            "epssPercentile": 0.56428,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61920",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a network.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00484,
            "epssPercentile": 0.39993,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61921",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00829,
            "epssPercentile": 0.55174,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61923",
            "title": "Windows Display Enhancement Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61924",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00829,
            "epssPercentile": 0.55173,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61925",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00381,
            "epssPercentile": 0.31232,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61926",
            "title": "Windows USB Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61928",
            "title": "Windows Hello Tampering Vulnerability",
            "summary": "Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0021,
            "epssPercentile": 0.11257,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61930",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02092,
            "epssPercentile": 0.80405,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61932",
            "title": "Windows DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.2356,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61936",
            "title": "Windows Defender Firewall Service Security Feature Bypass Vulnerability",
            "summary": "Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00282,
            "epssPercentile": 0.20397,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61937",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61939",
            "title": "Winlogon Elevation of Privilege Vulnerability",
            "summary": "Use after free in Winlogon allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15759,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62690",
            "title": "Windows Push Notifications Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62692",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62695",
            "title": "Windows Storage Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.2356,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62696",
            "title": "Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03401,
            "epssPercentile": 0.88059,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62698",
            "title": "Microsoft Digest Authentication Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00361,
            "epssPercentile": 0.29142,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62699",
            "title": "Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to execute code with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00409,
            "epssPercentile": 0.34136,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62700",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62701",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62702",
            "title": "Windows Graphics Kernel Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00943,
            "epssPercentile": 0.58737,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62703",
            "title": "Windows DWM Core Library Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31954,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62707",
            "title": "Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62709",
            "title": "Windows GDI+ Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31908,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62710",
            "title": "Windows Device Association Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62711",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23518,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62712",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0038,
            "epssPercentile": 0.31158,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62713",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0195,
            "epssPercentile": 0.78893,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62714",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00468,
            "epssPercentile": 0.3888,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62715",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0048,
            "epssPercentile": 0.3977,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62716",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00468,
            "epssPercentile": 0.3888,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62717",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62718",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0048,
            "epssPercentile": 0.39771,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62719",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62720",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00468,
            "epssPercentile": 0.3888,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62721",
            "title": "Windows User-Mode Power Service (UMPS) Elevation of Privilege Vulnerability",
            "summary": "Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0038,
            "epssPercentile": 0.31198,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62723",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62724",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15758,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62725",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09788,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62726",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15758,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62727",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00186,
            "epssPercentile": 0.08256,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62728",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62729",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62730",
            "title": "Windows Wired AutoConfig Service Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62732",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62733",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62734",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62735",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00476,
            "epssPercentile": 0.39473,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62738",
            "title": "Windows Management Instrumentation Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62739",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00249,
            "epssPercentile": 0.1616,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62740",
            "title": "Windows Imaging Component Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31908,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62741",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02092,
            "epssPercentile": 0.80405,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62742",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0048,
            "epssPercentile": 0.39771,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62743",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31954,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62745",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00361,
            "epssPercentile": 0.29156,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62746",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31954,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62747",
            "title": "Windows Device Association Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23557,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62748",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08564,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62750",
            "title": "Windows HTTP Protocol Stack Tampering Vulnerability",
            "summary": "Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00574,
            "epssPercentile": 0.45288,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62751",
            "title": "Windows Projected File System Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23557,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62752",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23556,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62753",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00207,
            "epssPercentile": 0.10799,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62754",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62755",
            "title": "Windows DHCP Client Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62757",
            "title": "Windows Schannel Security Feature Bypass Vulnerability",
            "summary": "Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00255,
            "epssPercentile": 0.16929,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62758",
            "title": "Windows Remote Access Connection Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.14966,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62761",
            "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00355,
            "epssPercentile": 0.28559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62768",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62769",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62770",
            "title": "Windows Shell Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15007,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62771",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00249,
            "epssPercentile": 0.1616,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62773",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09787,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62774",
            "title": "Windows Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09787,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62776",
            "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00271,
            "epssPercentile": 0.19237,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62777",
            "title": "Windows License Manager Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11773,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62778",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00506,
            "epssPercentile": 0.41401,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62781",
            "title": "RPC Runtime Library Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00519,
            "epssPercentile": 0.42242,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62782",
            "title": "Windows SMB Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00868,
            "epssPercentile": 0.56396,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62783",
            "title": "Windows Remote Access Connection Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01951,
            "epssPercentile": 0.78901,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62784",
            "title": "Microsoft Local Security Authority Server (lsasrv) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00934,
            "epssPercentile": 0.58442,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62785",
            "title": "Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00837,
            "epssPercentile": 0.55424,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62786",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62787",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows DNS allows an authorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0053,
            "epssPercentile": 0.4292,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62790",
            "title": "Windows SMBv3 Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00664,
            "epssPercentile": 0.49429,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62792",
            "title": "Windows TCP/IP Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00708,
            "epssPercentile": 0.51162,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62793",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23712,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62795",
            "title": "Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00607,
            "epssPercentile": 0.46873,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62796",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62797",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00334,
            "epssPercentile": 0.26156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62800",
            "title": "Windows SMBv3 Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00934,
            "epssPercentile": 0.58442,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62803",
            "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00371,
            "epssPercentile": 0.30191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62807",
            "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00371,
            "epssPercentile": 0.30191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62811",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00334,
            "epssPercentile": 0.26156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62812",
            "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00291,
            "epssPercentile": 0.21362,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62814",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00537,
            "epssPercentile": 0.43342,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62815",
            "title": "Microsoft QUIC Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00982,
            "epssPercentile": 0.6,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62816",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00393,
            "epssPercentile": 0.32547,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62817",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00668,
            "epssPercentile": 0.49598,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62818",
            "title": "Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability",
            "summary": "Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00972,
            "epssPercentile": 0.59701,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62819",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00579,
            "epssPercentile": 0.45525,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62820",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00543,
            "epssPercentile": 0.43643,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62822",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00633,
            "epssPercentile": 0.48082,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62823",
            "title": "Windows DHCP Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00662,
            "epssPercentile": 0.49371,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62832",
            "title": "Windows User Profile Service Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03295,
            "epssPercentile": 0.87687,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62876",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62877",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62878",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0126,
            "epssPercentile": 0.67668,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62880",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15004,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62881",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62883",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17628,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62885",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62887",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22166,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62888",
            "title": "Windows DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01951,
            "epssPercentile": 0.78901,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62889",
            "title": "Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability",
            "summary": "Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0056,
            "epssPercentile": 0.44552,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62890",
            "title": "Windows GDI+ Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00269,
            "epssPercentile": 0.18868,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62892",
            "title": "Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability",
            "summary": "Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09787,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62893",
            "title": "Windows Deployment Services TFTP Server Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02732,
            "epssPercentile": 0.85128,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62894",
            "title": "Windows DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00249,
            "epssPercentile": 0.16159,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62908",
            "title": "Windows Backup Engine Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00153,
            "epssPercentile": 0.04738,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65662",
            "title": "Windows GDI Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65671",
            "title": "Remote Access API Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00257,
            "epssPercentile": 0.17266,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65672",
            "title": "Remote Access API Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00257,
            "epssPercentile": 0.17267,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65678",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11662,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65679",
            "title": "Windows iSCSI Target Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00566,
            "epssPercentile": 0.44906,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65681",
            "title": "Windows iSCSI Target Service Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00886,
            "epssPercentile": 0.56926,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65773",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00242,
            "epssPercentile": 0.15314,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65774",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00257,
            "epssPercentile": 0.17266,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65775",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02609,
            "epssPercentile": 0.84381,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65777",
            "title": "Active Directory Security Feature Bypass Vulnerability",
            "summary": "Inadequate encryption strength in Windows Active Directory allows an authorized attacker to bypass a security feature over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00288,
            "epssPercentile": 0.21003,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65784",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00299,
            "epssPercentile": 0.22201,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65786",
            "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65787",
            "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.2356,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65789",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00544,
            "epssPercentile": 0.43722,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65790",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15007,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65791",
            "title": "Windows iSCSI Target Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.006,
            "epssPercentile": 0.46555,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65794",
            "title": "Windows SMB Client Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00651,
            "epssPercentile": 0.48924,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65795",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17627,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65796",
            "title": "Windows iSCSI Target Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00528,
            "epssPercentile": 0.42787,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65797",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17582,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65798",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17628,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65799",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00253,
            "epssPercentile": 0.16631,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65814",
            "title": "Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00252,
            "epssPercentile": 0.16578,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66799",
            "title": "Windows Key Guard Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00269,
            "epssPercentile": 0.18868,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66802",
            "title": "Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0036,
            "epssPercentile": 0.29053,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-6726",
            "title": "An information leakage vulnerability in the TCG TPM 2.0 reference code.",
            "summary": "An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key. See also TCG VRT0010.",
            "score": 7.9,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00215,
            "epssPercentile": 0.11783,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-6727",
            "title": "CVE-2026-6727",
            "summary": "A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with access to the TPM command interface may be able to exploit timing differences to recover information that could allow decryption of ciphertexts encrypted to TPM-managed RSA keys, including the RSA Endorsement Key (EK), including import blobs, credential blobs, and session salts. Under certain conditi",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00203,
            "epssPercentile": 0.10248,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68819",
            "title": "Windows Network File System Denial of Service Vulnerability",
            "summary": "Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00684,
            "epssPercentile": 0.50268,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68820",
            "title": "Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability",
            "summary": "Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2026-08-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.06184,
            "epssPercentile": 0.93023,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2026-08-25 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70304",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00316,
            "epssPercentile": 0.24068,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70307",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00322,
            "epssPercentile": 0.24811,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70330",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00316,
            "epssPercentile": 0.24068,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70344",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70345",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70346",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70347",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23517,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-71331",
            "title": "Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00454,
            "epssPercentile": 0.37968,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Exploitation reported by the vendor source",
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-65791",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-windows-kb5120233",
      "slug": "microsoft-2026-08-windows-kb5120233",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5120233",
      "title": "Deploy Microsoft Windows security update KB5120233",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5120233",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Windows Server 2025, Windows Server 2025 (Server Core installation)",
      "platform": "Windows",
      "release_version": "10.0.26100.33296",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 215 linked CVEs for Windows Server 2025, Windows Server 2025 (Server Core installation). Microsoft reports exploitation for CVE-2026-68820.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 215,
        "ids": [
          "CVE-2026-42976",
          "CVE-2026-49179",
          "CVE-2026-50472",
          "CVE-2026-54113",
          "CVE-2026-54984",
          "CVE-2026-56174",
          "CVE-2026-56179",
          "CVE-2026-59122",
          "CVE-2026-59125",
          "CVE-2026-59126",
          "CVE-2026-59127",
          "CVE-2026-59128",
          "CVE-2026-59130",
          "CVE-2026-59131",
          "CVE-2026-59132",
          "CVE-2026-59134",
          "CVE-2026-59135",
          "CVE-2026-59136",
          "CVE-2026-59137",
          "CVE-2026-59138",
          "CVE-2026-61345",
          "CVE-2026-61346",
          "CVE-2026-61347",
          "CVE-2026-61348",
          "CVE-2026-61349",
          "CVE-2026-61350",
          "CVE-2026-61352",
          "CVE-2026-61353",
          "CVE-2026-61355",
          "CVE-2026-61356",
          "CVE-2026-61357",
          "CVE-2026-61358",
          "CVE-2026-61359",
          "CVE-2026-61360",
          "CVE-2026-61361",
          "CVE-2026-61363",
          "CVE-2026-61364",
          "CVE-2026-61365",
          "CVE-2026-61366",
          "CVE-2026-61367",
          "CVE-2026-61368",
          "CVE-2026-61918",
          "CVE-2026-61920",
          "CVE-2026-61921",
          "CVE-2026-61923",
          "CVE-2026-61924",
          "CVE-2026-61925",
          "CVE-2026-61926",
          "CVE-2026-61927",
          "CVE-2026-61928",
          "CVE-2026-61929",
          "CVE-2026-61930",
          "CVE-2026-61933",
          "CVE-2026-61934",
          "CVE-2026-61936",
          "CVE-2026-61937",
          "CVE-2026-61938",
          "CVE-2026-61939",
          "CVE-2026-62690",
          "CVE-2026-62692",
          "CVE-2026-62695",
          "CVE-2026-62696",
          "CVE-2026-62698",
          "CVE-2026-62699",
          "CVE-2026-62700",
          "CVE-2026-62701",
          "CVE-2026-62702",
          "CVE-2026-62703",
          "CVE-2026-62707",
          "CVE-2026-62708",
          "CVE-2026-62709",
          "CVE-2026-62710",
          "CVE-2026-62711",
          "CVE-2026-62712",
          "CVE-2026-62713",
          "CVE-2026-62714",
          "CVE-2026-62715",
          "CVE-2026-62716",
          "CVE-2026-62717",
          "CVE-2026-62718",
          "CVE-2026-62719",
          "CVE-2026-62720",
          "CVE-2026-62721",
          "CVE-2026-62722",
          "CVE-2026-62723",
          "CVE-2026-62724",
          "CVE-2026-62725",
          "CVE-2026-62726",
          "CVE-2026-62727",
          "CVE-2026-62728",
          "CVE-2026-62729",
          "CVE-2026-62730",
          "CVE-2026-62732",
          "CVE-2026-62733",
          "CVE-2026-62734",
          "CVE-2026-62735",
          "CVE-2026-62736",
          "CVE-2026-62737",
          "CVE-2026-62738",
          "CVE-2026-62739",
          "CVE-2026-62740",
          "CVE-2026-62741",
          "CVE-2026-62742",
          "CVE-2026-62743",
          "CVE-2026-62745",
          "CVE-2026-62746",
          "CVE-2026-62747",
          "CVE-2026-62748",
          "CVE-2026-62749",
          "CVE-2026-62750",
          "CVE-2026-62751",
          "CVE-2026-62752",
          "CVE-2026-62753",
          "CVE-2026-62754",
          "CVE-2026-62755",
          "CVE-2026-62757",
          "CVE-2026-62758",
          "CVE-2026-62761",
          "CVE-2026-62766",
          "CVE-2026-62768",
          "CVE-2026-62769",
          "CVE-2026-62770",
          "CVE-2026-62771",
          "CVE-2026-62773",
          "CVE-2026-62774",
          "CVE-2026-62776",
          "CVE-2026-62777",
          "CVE-2026-62778",
          "CVE-2026-62779",
          "CVE-2026-62780",
          "CVE-2026-62781",
          "CVE-2026-62782",
          "CVE-2026-62783",
          "CVE-2026-62784",
          "CVE-2026-62785",
          "CVE-2026-62786",
          "CVE-2026-62787",
          "CVE-2026-62788",
          "CVE-2026-62790",
          "CVE-2026-62792",
          "CVE-2026-62793",
          "CVE-2026-62795",
          "CVE-2026-62796",
          "CVE-2026-62797",
          "CVE-2026-62798",
          "CVE-2026-62800",
          "CVE-2026-62803",
          "CVE-2026-62807",
          "CVE-2026-62811",
          "CVE-2026-62812",
          "CVE-2026-62814",
          "CVE-2026-62815",
          "CVE-2026-62816",
          "CVE-2026-62817",
          "CVE-2026-62818",
          "CVE-2026-62819",
          "CVE-2026-62820",
          "CVE-2026-62822",
          "CVE-2026-62823",
          "CVE-2026-62832",
          "CVE-2026-62876",
          "CVE-2026-62877",
          "CVE-2026-62878",
          "CVE-2026-62880",
          "CVE-2026-62881",
          "CVE-2026-62883",
          "CVE-2026-62885",
          "CVE-2026-62887",
          "CVE-2026-62888",
          "CVE-2026-62889",
          "CVE-2026-62890",
          "CVE-2026-62892",
          "CVE-2026-62893",
          "CVE-2026-62894",
          "CVE-2026-62908",
          "CVE-2026-65662",
          "CVE-2026-65671",
          "CVE-2026-65672",
          "CVE-2026-65678",
          "CVE-2026-65679",
          "CVE-2026-65681",
          "CVE-2026-65773",
          "CVE-2026-65774",
          "CVE-2026-65775",
          "CVE-2026-65776",
          "CVE-2026-65777",
          "CVE-2026-65784",
          "CVE-2026-65785",
          "CVE-2026-65786",
          "CVE-2026-65787",
          "CVE-2026-65788",
          "CVE-2026-65789",
          "CVE-2026-65790",
          "CVE-2026-65791",
          "CVE-2026-65794",
          "CVE-2026-65795",
          "CVE-2026-65796",
          "CVE-2026-65797",
          "CVE-2026-65798",
          "CVE-2026-65799",
          "CVE-2026-65814",
          "CVE-2026-66799",
          "CVE-2026-66802",
          "CVE-2026-6726",
          "CVE-2026-6727",
          "CVE-2026-68819",
          "CVE-2026-68820",
          "CVE-2026-70304",
          "CVE-2026-70307",
          "CVE-2026-70330",
          "CVE-2026-70344",
          "CVE-2026-70345",
          "CVE-2026-70346",
          "CVE-2026-70347",
          "CVE-2026-71331"
        ],
        "details": [
          {
            "id": "CVE-2026-42976",
            "title": "Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11772,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49179",
            "title": "Windows Active Directory Domain Services Remote Code Execution Vulnerability",
            "summary": "Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00831,
            "epssPercentile": 0.55217,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50472",
            "title": "Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54113",
            "title": "Remote Procedure Call Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01126,
            "epssPercentile": 0.64162,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54984",
            "title": "Windows Imaging Component Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.006,
            "epssPercentile": 0.46535,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56174",
            "title": "Windows Narrator Braille Elevation of Privilege Vulnerability",
            "summary": "Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00291,
            "epssPercentile": 0.21293,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56179",
            "title": "Windows Network Address Translation (NAT) Spoofing Vulnerability",
            "summary": "Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.",
            "score": 8.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00234,
            "epssPercentile": 0.14223,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59122",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59125",
            "title": "Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability",
            "summary": "Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59126",
            "title": "Windows Event Logging Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59127",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23557,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59128",
            "title": "Windows Encrypting File System (EFS) Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31953,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59130",
            "title": "AMD Zen Information Disclosure Vulnerability",
            "summary": "No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00337,
            "epssPercentile": 0.26512,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59131",
            "title": "AMD Zen Information Disclosure Vulnerability",
            "summary": "No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00284,
            "epssPercentile": 0.20673,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59132",
            "title": "Windows TCP/IP Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01686,
            "epssPercentile": 0.75496,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59134",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00624,
            "epssPercentile": 0.47693,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59135",
            "title": "Microsoft Windows Search Component Information Disclosure Vulnerability",
            "summary": "Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0032,
            "epssPercentile": 0.24552,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59136",
            "title": "Microsoft COM for Windows Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0037,
            "epssPercentile": 0.30138,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59137",
            "title": "Windows Event Logging Service Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31953,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59138",
            "title": "Microsoft Remote Registry Service Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01042,
            "epssPercentile": 0.61833,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61345",
            "title": "Microsoft Remote Registry Service Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01042,
            "epssPercentile": 0.61834,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61346",
            "title": "Windows Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61347",
            "title": "Windows Event Logging Service Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61348",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0159,
            "epssPercentile": 0.7403,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61349",
            "title": "Windows Work Folder Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00238,
            "epssPercentile": 0.14813,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61350",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00449,
            "epssPercentile": 0.3762,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61352",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00428,
            "epssPercentile": 0.35876,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61353",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61355",
            "title": "Windows Sensor Data Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23556,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61356",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61357",
            "title": "Application Information Services Elevation of Privilege Vulnerability",
            "summary": "Use after free in Application Information Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23556,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61358",
            "title": "Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0368,
            "epssPercentile": 0.88942,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61359",
            "title": "Windows Storage Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00334,
            "epssPercentile": 0.26154,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61360",
            "title": "Windows GDI Information Disclosure Vulnerability",
            "summary": "Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31956,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61361",
            "title": "Windows DHCP Client Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows DHCP Client allows an authorized attacker to execute code locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61363",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00625,
            "epssPercentile": 0.47727,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61364",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61365",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61366",
            "title": "Windows Network Connection Broker Elevation of Privilege Vulnerability",
            "summary": "Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61367",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61368",
            "title": "Windows Hyper-V Information Disclosure Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally.",
            "score": 5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00372,
            "epssPercentile": 0.30393,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61918",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00869,
            "epssPercentile": 0.56428,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61920",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a network.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00484,
            "epssPercentile": 0.39993,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61921",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00829,
            "epssPercentile": 0.55174,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61923",
            "title": "Windows Display Enhancement Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61924",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00829,
            "epssPercentile": 0.55173,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61925",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00381,
            "epssPercentile": 0.31232,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61926",
            "title": "Windows USB Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61927",
            "title": "Windows Bind Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08564,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61928",
            "title": "Windows Hello Tampering Vulnerability",
            "summary": "Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0021,
            "epssPercentile": 0.11257,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61929",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01676,
            "epssPercentile": 0.75331,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61930",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02092,
            "epssPercentile": 0.80405,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61933",
            "title": "Windows DWM Core Library Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61934",
            "title": "Windows Bind Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61936",
            "title": "Windows Defender Firewall Service Security Feature Bypass Vulnerability",
            "summary": "Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00282,
            "epssPercentile": 0.20397,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61937",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61938",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61939",
            "title": "Winlogon Elevation of Privilege Vulnerability",
            "summary": "Use after free in Winlogon allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15759,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62690",
            "title": "Windows Push Notifications Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62692",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62695",
            "title": "Windows Storage Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.2356,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62696",
            "title": "Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03401,
            "epssPercentile": 0.88059,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62698",
            "title": "Microsoft Digest Authentication Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00361,
            "epssPercentile": 0.29142,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62699",
            "title": "Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to execute code with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00409,
            "epssPercentile": 0.34136,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62700",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62701",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62702",
            "title": "Windows Graphics Kernel Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00943,
            "epssPercentile": 0.58737,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62703",
            "title": "Windows DWM Core Library Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31954,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62707",
            "title": "Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62708",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00316,
            "epssPercentile": 0.24162,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62709",
            "title": "Windows GDI+ Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31908,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62710",
            "title": "Windows Device Association Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62711",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23518,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62712",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0038,
            "epssPercentile": 0.31158,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62713",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0195,
            "epssPercentile": 0.78893,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62714",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00468,
            "epssPercentile": 0.3888,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62715",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0048,
            "epssPercentile": 0.3977,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62716",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00468,
            "epssPercentile": 0.3888,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62717",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62718",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0048,
            "epssPercentile": 0.39771,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62719",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62720",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00468,
            "epssPercentile": 0.3888,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62721",
            "title": "Windows User-Mode Power Service (UMPS) Elevation of Privilege Vulnerability",
            "summary": "Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0038,
            "epssPercentile": 0.31198,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62722",
            "title": "Microsoft Brokering File System Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Brokering File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62723",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62724",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15758,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62725",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09788,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62726",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15758,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62727",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00186,
            "epssPercentile": 0.08256,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62728",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62729",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62730",
            "title": "Windows Wired AutoConfig Service Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62732",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62733",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62734",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62735",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00476,
            "epssPercentile": 0.39473,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62736",
            "title": "Windows DHCP Client Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15004,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62737",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02844,
            "epssPercentile": 0.85765,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62738",
            "title": "Windows Management Instrumentation Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62739",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00249,
            "epssPercentile": 0.1616,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62740",
            "title": "Windows Imaging Component Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31908,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62741",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02092,
            "epssPercentile": 0.80405,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62742",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0048,
            "epssPercentile": 0.39771,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62743",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31954,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62745",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00361,
            "epssPercentile": 0.29156,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62746",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31954,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62747",
            "title": "Windows Device Association Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23557,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62748",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08564,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62749",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09786,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62750",
            "title": "Windows HTTP Protocol Stack Tampering Vulnerability",
            "summary": "Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00574,
            "epssPercentile": 0.45288,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62751",
            "title": "Windows Projected File System Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23557,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62752",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23556,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62753",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00207,
            "epssPercentile": 0.10799,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62754",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62755",
            "title": "Windows DHCP Client Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62757",
            "title": "Windows Schannel Security Feature Bypass Vulnerability",
            "summary": "Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00255,
            "epssPercentile": 0.16929,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62758",
            "title": "Windows Remote Access Connection Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.14966,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62761",
            "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00355,
            "epssPercentile": 0.28559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62766",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Double free in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01522,
            "epssPercentile": 0.72941,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62768",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62769",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62770",
            "title": "Windows Shell Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15007,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62771",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00249,
            "epssPercentile": 0.1616,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62773",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09787,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62774",
            "title": "Windows Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09787,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62776",
            "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00271,
            "epssPercentile": 0.19237,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62777",
            "title": "Windows License Manager Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11773,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62778",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00506,
            "epssPercentile": 0.41401,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62779",
            "title": "Windows Schannel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Schannel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62780",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10199,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62781",
            "title": "RPC Runtime Library Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00519,
            "epssPercentile": 0.42242,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62782",
            "title": "Windows SMB Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00868,
            "epssPercentile": 0.56396,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62783",
            "title": "Windows Remote Access Connection Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01951,
            "epssPercentile": 0.78901,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62784",
            "title": "Microsoft Local Security Authority Server (lsasrv) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00934,
            "epssPercentile": 0.58442,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62785",
            "title": "Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00837,
            "epssPercentile": 0.55424,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62786",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62787",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows DNS allows an authorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0053,
            "epssPercentile": 0.4292,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62788",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26033,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62790",
            "title": "Windows SMBv3 Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00664,
            "epssPercentile": 0.49429,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62792",
            "title": "Windows TCP/IP Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00708,
            "epssPercentile": 0.51162,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62793",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23712,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62795",
            "title": "Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00607,
            "epssPercentile": 0.46873,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62796",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62797",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00334,
            "epssPercentile": 0.26156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62798",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23712,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62800",
            "title": "Windows SMBv3 Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00934,
            "epssPercentile": 0.58442,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62803",
            "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00371,
            "epssPercentile": 0.30191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62807",
            "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00371,
            "epssPercentile": 0.30191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62811",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00334,
            "epssPercentile": 0.26156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62812",
            "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00291,
            "epssPercentile": 0.21362,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62814",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00537,
            "epssPercentile": 0.43342,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62815",
            "title": "Microsoft QUIC Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00982,
            "epssPercentile": 0.6,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62816",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00393,
            "epssPercentile": 0.32547,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62817",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00668,
            "epssPercentile": 0.49598,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62818",
            "title": "Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability",
            "summary": "Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00972,
            "epssPercentile": 0.59701,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62819",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00579,
            "epssPercentile": 0.45525,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62820",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00543,
            "epssPercentile": 0.43643,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62822",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00633,
            "epssPercentile": 0.48082,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62823",
            "title": "Windows DHCP Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00662,
            "epssPercentile": 0.49371,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62832",
            "title": "Windows User Profile Service Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03295,
            "epssPercentile": 0.87687,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62876",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62877",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62878",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0126,
            "epssPercentile": 0.67668,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62880",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15004,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62881",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62883",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17628,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62885",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62887",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22166,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62888",
            "title": "Windows DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01951,
            "epssPercentile": 0.78901,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62889",
            "title": "Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability",
            "summary": "Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0056,
            "epssPercentile": 0.44552,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62890",
            "title": "Windows GDI+ Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00269,
            "epssPercentile": 0.18868,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62892",
            "title": "Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability",
            "summary": "Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09787,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62893",
            "title": "Windows Deployment Services TFTP Server Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02732,
            "epssPercentile": 0.85128,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62894",
            "title": "Windows DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00249,
            "epssPercentile": 0.16159,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62908",
            "title": "Windows Backup Engine Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00153,
            "epssPercentile": 0.04738,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65662",
            "title": "Windows GDI Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65671",
            "title": "Remote Access API Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00257,
            "epssPercentile": 0.17266,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65672",
            "title": "Remote Access API Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00257,
            "epssPercentile": 0.17267,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65678",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11662,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65679",
            "title": "Windows iSCSI Target Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00566,
            "epssPercentile": 0.44906,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65681",
            "title": "Windows iSCSI Target Service Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00886,
            "epssPercentile": 0.56926,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65773",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00242,
            "epssPercentile": 0.15314,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65774",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00257,
            "epssPercentile": 0.17266,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65775",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02609,
            "epssPercentile": 0.84381,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65776",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00225,
            "epssPercentile": 0.13105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65777",
            "title": "Active Directory Security Feature Bypass Vulnerability",
            "summary": "Inadequate encryption strength in Windows Active Directory allows an authorized attacker to bypass a security feature over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00288,
            "epssPercentile": 0.21003,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65784",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00299,
            "epssPercentile": 0.22201,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65785",
            "title": "Windows DHCP Client Denial of Service Vulnerability",
            "summary": "Uncontrolled resource consumption in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00378,
            "epssPercentile": 0.30924,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65786",
            "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65787",
            "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.2356,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65788",
            "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
            "summary": "Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01676,
            "epssPercentile": 0.75331,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65789",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00544,
            "epssPercentile": 0.43722,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65790",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15007,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65791",
            "title": "Windows iSCSI Target Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.006,
            "epssPercentile": 0.46555,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65794",
            "title": "Windows SMB Client Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00651,
            "epssPercentile": 0.48924,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65795",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17627,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65796",
            "title": "Windows iSCSI Target Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00528,
            "epssPercentile": 0.42787,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65797",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17582,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65798",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17628,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65799",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00253,
            "epssPercentile": 0.16631,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65814",
            "title": "Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00252,
            "epssPercentile": 0.16578,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66799",
            "title": "Windows Key Guard Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00269,
            "epssPercentile": 0.18868,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66802",
            "title": "Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0036,
            "epssPercentile": 0.29053,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-6726",
            "title": "An information leakage vulnerability in the TCG TPM 2.0 reference code.",
            "summary": "An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key. See also TCG VRT0010.",
            "score": 7.9,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00215,
            "epssPercentile": 0.11783,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-6727",
            "title": "CVE-2026-6727",
            "summary": "A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with access to the TPM command interface may be able to exploit timing differences to recover information that could allow decryption of ciphertexts encrypted to TPM-managed RSA keys, including the RSA Endorsement Key (EK), including import blobs, credential blobs, and session salts. Under certain conditi",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00203,
            "epssPercentile": 0.10248,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68819",
            "title": "Windows Network File System Denial of Service Vulnerability",
            "summary": "Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00684,
            "epssPercentile": 0.50268,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68820",
            "title": "Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability",
            "summary": "Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2026-08-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.06184,
            "epssPercentile": 0.93023,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2026-08-25 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70304",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00316,
            "epssPercentile": 0.24068,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70307",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00322,
            "epssPercentile": 0.24811,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70330",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00316,
            "epssPercentile": 0.24068,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70344",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70345",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70346",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70347",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23517,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-71331",
            "title": "Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00454,
            "epssPercentile": 0.37968,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Exploitation reported by the vendor source",
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-65791",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-windows-kb5120238",
      "slug": "microsoft-2026-08-windows-kb5120238",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5120238",
      "title": "Deploy Microsoft Windows security update KB5120238",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5120238",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, plus 1 more",
      "platform": "Windows",
      "release_version": "10.0.17763.9121",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 183 linked CVEs for Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, plus 1 more. Microsoft reports exploitation for CVE-2026-68820.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 183,
        "ids": [
          "CVE-2026-42976",
          "CVE-2026-49179",
          "CVE-2026-50472",
          "CVE-2026-54113",
          "CVE-2026-54984",
          "CVE-2026-56174",
          "CVE-2026-59122",
          "CVE-2026-59125",
          "CVE-2026-59127",
          "CVE-2026-59128",
          "CVE-2026-59130",
          "CVE-2026-59131",
          "CVE-2026-59132",
          "CVE-2026-59134",
          "CVE-2026-59135",
          "CVE-2026-59136",
          "CVE-2026-59137",
          "CVE-2026-59138",
          "CVE-2026-61345",
          "CVE-2026-61346",
          "CVE-2026-61347",
          "CVE-2026-61348",
          "CVE-2026-61349",
          "CVE-2026-61350",
          "CVE-2026-61352",
          "CVE-2026-61353",
          "CVE-2026-61356",
          "CVE-2026-61358",
          "CVE-2026-61360",
          "CVE-2026-61363",
          "CVE-2026-61364",
          "CVE-2026-61365",
          "CVE-2026-61366",
          "CVE-2026-61367",
          "CVE-2026-61368",
          "CVE-2026-61918",
          "CVE-2026-61920",
          "CVE-2026-61921",
          "CVE-2026-61923",
          "CVE-2026-61924",
          "CVE-2026-61925",
          "CVE-2026-61926",
          "CVE-2026-61928",
          "CVE-2026-61930",
          "CVE-2026-61932",
          "CVE-2026-61936",
          "CVE-2026-61937",
          "CVE-2026-61939",
          "CVE-2026-62690",
          "CVE-2026-62692",
          "CVE-2026-62696",
          "CVE-2026-62698",
          "CVE-2026-62699",
          "CVE-2026-62700",
          "CVE-2026-62701",
          "CVE-2026-62703",
          "CVE-2026-62707",
          "CVE-2026-62709",
          "CVE-2026-62710",
          "CVE-2026-62711",
          "CVE-2026-62712",
          "CVE-2026-62713",
          "CVE-2026-62714",
          "CVE-2026-62715",
          "CVE-2026-62716",
          "CVE-2026-62717",
          "CVE-2026-62718",
          "CVE-2026-62719",
          "CVE-2026-62720",
          "CVE-2026-62721",
          "CVE-2026-62723",
          "CVE-2026-62724",
          "CVE-2026-62725",
          "CVE-2026-62726",
          "CVE-2026-62727",
          "CVE-2026-62728",
          "CVE-2026-62729",
          "CVE-2026-62730",
          "CVE-2026-62732",
          "CVE-2026-62733",
          "CVE-2026-62734",
          "CVE-2026-62735",
          "CVE-2026-62738",
          "CVE-2026-62739",
          "CVE-2026-62740",
          "CVE-2026-62741",
          "CVE-2026-62742",
          "CVE-2026-62743",
          "CVE-2026-62745",
          "CVE-2026-62746",
          "CVE-2026-62747",
          "CVE-2026-62748",
          "CVE-2026-62750",
          "CVE-2026-62752",
          "CVE-2026-62753",
          "CVE-2026-62754",
          "CVE-2026-62755",
          "CVE-2026-62757",
          "CVE-2026-62758",
          "CVE-2026-62761",
          "CVE-2026-62768",
          "CVE-2026-62769",
          "CVE-2026-62770",
          "CVE-2026-62771",
          "CVE-2026-62773",
          "CVE-2026-62774",
          "CVE-2026-62776",
          "CVE-2026-62777",
          "CVE-2026-62778",
          "CVE-2026-62781",
          "CVE-2026-62782",
          "CVE-2026-62783",
          "CVE-2026-62784",
          "CVE-2026-62785",
          "CVE-2026-62786",
          "CVE-2026-62787",
          "CVE-2026-62790",
          "CVE-2026-62792",
          "CVE-2026-62793",
          "CVE-2026-62795",
          "CVE-2026-62796",
          "CVE-2026-62797",
          "CVE-2026-62800",
          "CVE-2026-62803",
          "CVE-2026-62807",
          "CVE-2026-62812",
          "CVE-2026-62814",
          "CVE-2026-62816",
          "CVE-2026-62817",
          "CVE-2026-62818",
          "CVE-2026-62819",
          "CVE-2026-62820",
          "CVE-2026-62822",
          "CVE-2026-62823",
          "CVE-2026-62876",
          "CVE-2026-62877",
          "CVE-2026-62878",
          "CVE-2026-62880",
          "CVE-2026-62881",
          "CVE-2026-62883",
          "CVE-2026-62885",
          "CVE-2026-62887",
          "CVE-2026-62889",
          "CVE-2026-62890",
          "CVE-2026-62892",
          "CVE-2026-62893",
          "CVE-2026-62894",
          "CVE-2026-62908",
          "CVE-2026-65662",
          "CVE-2026-65671",
          "CVE-2026-65678",
          "CVE-2026-65679",
          "CVE-2026-65681",
          "CVE-2026-65773",
          "CVE-2026-65774",
          "CVE-2026-65775",
          "CVE-2026-65784",
          "CVE-2026-65786",
          "CVE-2026-65787",
          "CVE-2026-65789",
          "CVE-2026-65790",
          "CVE-2026-65791",
          "CVE-2026-65794",
          "CVE-2026-65795",
          "CVE-2026-65796",
          "CVE-2026-65797",
          "CVE-2026-65798",
          "CVE-2026-65799",
          "CVE-2026-65814",
          "CVE-2026-66799",
          "CVE-2026-66802",
          "CVE-2026-6726",
          "CVE-2026-6727",
          "CVE-2026-68819",
          "CVE-2026-68820",
          "CVE-2026-70304",
          "CVE-2026-70307",
          "CVE-2026-70330",
          "CVE-2026-70344",
          "CVE-2026-70345",
          "CVE-2026-70346",
          "CVE-2026-70347",
          "CVE-2026-71331"
        ],
        "details": [
          {
            "id": "CVE-2026-42976",
            "title": "Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11772,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49179",
            "title": "Windows Active Directory Domain Services Remote Code Execution Vulnerability",
            "summary": "Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00831,
            "epssPercentile": 0.55217,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50472",
            "title": "Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54113",
            "title": "Remote Procedure Call Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01126,
            "epssPercentile": 0.64162,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54984",
            "title": "Windows Imaging Component Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.006,
            "epssPercentile": 0.46535,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56174",
            "title": "Windows Narrator Braille Elevation of Privilege Vulnerability",
            "summary": "Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00291,
            "epssPercentile": 0.21293,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59122",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59125",
            "title": "Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability",
            "summary": "Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59127",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23557,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59128",
            "title": "Windows Encrypting File System (EFS) Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31953,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59130",
            "title": "AMD Zen Information Disclosure Vulnerability",
            "summary": "No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00337,
            "epssPercentile": 0.26512,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59131",
            "title": "AMD Zen Information Disclosure Vulnerability",
            "summary": "No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00284,
            "epssPercentile": 0.20673,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59132",
            "title": "Windows TCP/IP Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01686,
            "epssPercentile": 0.75496,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59134",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00624,
            "epssPercentile": 0.47693,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59135",
            "title": "Microsoft Windows Search Component Information Disclosure Vulnerability",
            "summary": "Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0032,
            "epssPercentile": 0.24552,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59136",
            "title": "Microsoft COM for Windows Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0037,
            "epssPercentile": 0.30138,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59137",
            "title": "Windows Event Logging Service Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31953,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59138",
            "title": "Microsoft Remote Registry Service Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01042,
            "epssPercentile": 0.61833,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61345",
            "title": "Microsoft Remote Registry Service Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01042,
            "epssPercentile": 0.61834,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61346",
            "title": "Windows Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61347",
            "title": "Windows Event Logging Service Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61348",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0159,
            "epssPercentile": 0.7403,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61349",
            "title": "Windows Work Folder Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00238,
            "epssPercentile": 0.14813,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61350",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00449,
            "epssPercentile": 0.3762,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61352",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00428,
            "epssPercentile": 0.35876,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61353",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61356",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61358",
            "title": "Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0368,
            "epssPercentile": 0.88942,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61360",
            "title": "Windows GDI Information Disclosure Vulnerability",
            "summary": "Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31956,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61363",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00625,
            "epssPercentile": 0.47727,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61364",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61365",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61366",
            "title": "Windows Network Connection Broker Elevation of Privilege Vulnerability",
            "summary": "Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61367",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61368",
            "title": "Windows Hyper-V Information Disclosure Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally.",
            "score": 5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00372,
            "epssPercentile": 0.30393,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61918",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00869,
            "epssPercentile": 0.56428,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61920",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a network.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00484,
            "epssPercentile": 0.39993,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61921",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00829,
            "epssPercentile": 0.55174,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61923",
            "title": "Windows Display Enhancement Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61924",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00829,
            "epssPercentile": 0.55173,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61925",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00381,
            "epssPercentile": 0.31232,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61926",
            "title": "Windows USB Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61928",
            "title": "Windows Hello Tampering Vulnerability",
            "summary": "Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0021,
            "epssPercentile": 0.11257,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61930",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02092,
            "epssPercentile": 0.80405,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61932",
            "title": "Windows DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.2356,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61936",
            "title": "Windows Defender Firewall Service Security Feature Bypass Vulnerability",
            "summary": "Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00282,
            "epssPercentile": 0.20397,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61937",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61939",
            "title": "Winlogon Elevation of Privilege Vulnerability",
            "summary": "Use after free in Winlogon allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15759,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62690",
            "title": "Windows Push Notifications Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62692",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62696",
            "title": "Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03401,
            "epssPercentile": 0.88059,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62698",
            "title": "Microsoft Digest Authentication Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00361,
            "epssPercentile": 0.29142,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62699",
            "title": "Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to execute code with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00409,
            "epssPercentile": 0.34136,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62700",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62701",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62703",
            "title": "Windows DWM Core Library Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31954,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62707",
            "title": "Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62709",
            "title": "Windows GDI+ Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31908,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62710",
            "title": "Windows Device Association Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62711",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23518,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62712",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0038,
            "epssPercentile": 0.31158,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62713",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0195,
            "epssPercentile": 0.78893,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62714",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00468,
            "epssPercentile": 0.3888,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62715",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0048,
            "epssPercentile": 0.3977,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62716",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00468,
            "epssPercentile": 0.3888,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62717",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62718",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0048,
            "epssPercentile": 0.39771,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62719",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62720",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00468,
            "epssPercentile": 0.3888,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62721",
            "title": "Windows User-Mode Power Service (UMPS) Elevation of Privilege Vulnerability",
            "summary": "Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0038,
            "epssPercentile": 0.31198,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62723",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62724",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15758,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62725",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09788,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62726",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15758,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62727",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00186,
            "epssPercentile": 0.08256,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62728",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62729",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62730",
            "title": "Windows Wired AutoConfig Service Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62732",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62733",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62734",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62735",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00476,
            "epssPercentile": 0.39473,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62738",
            "title": "Windows Management Instrumentation Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62739",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00249,
            "epssPercentile": 0.1616,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62740",
            "title": "Windows Imaging Component Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31908,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62741",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02092,
            "epssPercentile": 0.80405,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62742",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0048,
            "epssPercentile": 0.39771,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62743",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31954,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62745",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00361,
            "epssPercentile": 0.29156,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62746",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31954,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62747",
            "title": "Windows Device Association Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23557,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62748",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08564,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62750",
            "title": "Windows HTTP Protocol Stack Tampering Vulnerability",
            "summary": "Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00574,
            "epssPercentile": 0.45288,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62752",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23556,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62753",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00207,
            "epssPercentile": 0.10799,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62754",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62755",
            "title": "Windows DHCP Client Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62757",
            "title": "Windows Schannel Security Feature Bypass Vulnerability",
            "summary": "Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00255,
            "epssPercentile": 0.16929,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62758",
            "title": "Windows Remote Access Connection Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.14966,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62761",
            "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00355,
            "epssPercentile": 0.28559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62768",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62769",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62770",
            "title": "Windows Shell Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15007,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62771",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00249,
            "epssPercentile": 0.1616,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62773",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09787,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62774",
            "title": "Windows Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09787,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62776",
            "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00271,
            "epssPercentile": 0.19237,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62777",
            "title": "Windows License Manager Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11773,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62778",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00506,
            "epssPercentile": 0.41401,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62781",
            "title": "RPC Runtime Library Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00519,
            "epssPercentile": 0.42242,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62782",
            "title": "Windows SMB Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00868,
            "epssPercentile": 0.56396,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62783",
            "title": "Windows Remote Access Connection Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01951,
            "epssPercentile": 0.78901,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62784",
            "title": "Microsoft Local Security Authority Server (lsasrv) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00934,
            "epssPercentile": 0.58442,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62785",
            "title": "Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00837,
            "epssPercentile": 0.55424,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62786",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62787",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows DNS allows an authorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0053,
            "epssPercentile": 0.4292,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62790",
            "title": "Windows SMBv3 Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00664,
            "epssPercentile": 0.49429,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62792",
            "title": "Windows TCP/IP Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00708,
            "epssPercentile": 0.51162,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62793",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23712,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62795",
            "title": "Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00607,
            "epssPercentile": 0.46873,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62796",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62797",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00334,
            "epssPercentile": 0.26156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62800",
            "title": "Windows SMBv3 Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00934,
            "epssPercentile": 0.58442,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62803",
            "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00371,
            "epssPercentile": 0.30191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62807",
            "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00371,
            "epssPercentile": 0.30191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62812",
            "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00291,
            "epssPercentile": 0.21362,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62814",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00537,
            "epssPercentile": 0.43342,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62816",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00393,
            "epssPercentile": 0.32547,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62817",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00668,
            "epssPercentile": 0.49598,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62818",
            "title": "Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability",
            "summary": "Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00972,
            "epssPercentile": 0.59701,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62819",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00579,
            "epssPercentile": 0.45525,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62820",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00543,
            "epssPercentile": 0.43643,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62822",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00633,
            "epssPercentile": 0.48082,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62823",
            "title": "Windows DHCP Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00662,
            "epssPercentile": 0.49371,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62876",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62877",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62878",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0126,
            "epssPercentile": 0.67668,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62880",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15004,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62881",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62883",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17628,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62885",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62887",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22166,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62889",
            "title": "Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability",
            "summary": "Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0056,
            "epssPercentile": 0.44552,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62890",
            "title": "Windows GDI+ Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00269,
            "epssPercentile": 0.18868,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62892",
            "title": "Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability",
            "summary": "Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09787,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62893",
            "title": "Windows Deployment Services TFTP Server Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02732,
            "epssPercentile": 0.85128,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62894",
            "title": "Windows DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00249,
            "epssPercentile": 0.16159,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62908",
            "title": "Windows Backup Engine Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00153,
            "epssPercentile": 0.04738,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65662",
            "title": "Windows GDI Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65671",
            "title": "Remote Access API Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00257,
            "epssPercentile": 0.17266,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65678",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11662,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65679",
            "title": "Windows iSCSI Target Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00566,
            "epssPercentile": 0.44906,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65681",
            "title": "Windows iSCSI Target Service Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00886,
            "epssPercentile": 0.56926,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65773",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00242,
            "epssPercentile": 0.15314,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65774",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00257,
            "epssPercentile": 0.17266,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65775",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02609,
            "epssPercentile": 0.84381,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65784",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00299,
            "epssPercentile": 0.22201,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65786",
            "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65787",
            "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.2356,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65789",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00544,
            "epssPercentile": 0.43722,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65790",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15007,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65791",
            "title": "Windows iSCSI Target Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.006,
            "epssPercentile": 0.46555,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65794",
            "title": "Windows SMB Client Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00651,
            "epssPercentile": 0.48924,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65795",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17627,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65796",
            "title": "Windows iSCSI Target Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00528,
            "epssPercentile": 0.42787,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65797",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17582,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65798",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17628,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65799",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00253,
            "epssPercentile": 0.16631,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65814",
            "title": "Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00252,
            "epssPercentile": 0.16578,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66799",
            "title": "Windows Key Guard Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00269,
            "epssPercentile": 0.18868,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66802",
            "title": "Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0036,
            "epssPercentile": 0.29053,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-6726",
            "title": "An information leakage vulnerability in the TCG TPM 2.0 reference code.",
            "summary": "An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key. See also TCG VRT0010.",
            "score": 7.9,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00215,
            "epssPercentile": 0.11783,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-6727",
            "title": "CVE-2026-6727",
            "summary": "A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with access to the TPM command interface may be able to exploit timing differences to recover information that could allow decryption of ciphertexts encrypted to TPM-managed RSA keys, including the RSA Endorsement Key (EK), including import blobs, credential blobs, and session salts. Under certain conditi",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00203,
            "epssPercentile": 0.10248,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68819",
            "title": "Windows Network File System Denial of Service Vulnerability",
            "summary": "Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00684,
            "epssPercentile": 0.50268,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68820",
            "title": "Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability",
            "summary": "Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2026-08-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.06184,
            "epssPercentile": 0.93023,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2026-08-25 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70304",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00316,
            "epssPercentile": 0.24068,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70307",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00322,
            "epssPercentile": 0.24811,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70330",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00316,
            "epssPercentile": 0.24068,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70344",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70345",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70346",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70347",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23517,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-71331",
            "title": "Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00454,
            "epssPercentile": 0.37968,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Exploitation reported by the vendor source",
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-65791",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-windows-kb5120240",
      "slug": "microsoft-2026-08-windows-kb5120240",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5120240",
      "title": "Deploy Microsoft Windows security update KB5120240",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5120240",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Windows 11 Version 23H2 for ARM64-based Systems, Windows 11 Version 23H2 for x64-based Systems",
      "platform": "Windows",
      "release_version": "10.0.22631.7517",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 171 linked CVEs for Windows 11 Version 23H2 for ARM64-based Systems, Windows 11 Version 23H2 for x64-based Systems. Microsoft reports exploitation for CVE-2026-68820.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 171,
        "ids": [
          "CVE-2026-49179",
          "CVE-2026-50472",
          "CVE-2026-54113",
          "CVE-2026-54984",
          "CVE-2026-56174",
          "CVE-2026-59122",
          "CVE-2026-59125",
          "CVE-2026-59126",
          "CVE-2026-59127",
          "CVE-2026-59128",
          "CVE-2026-59130",
          "CVE-2026-59131",
          "CVE-2026-59132",
          "CVE-2026-59134",
          "CVE-2026-59135",
          "CVE-2026-59136",
          "CVE-2026-59137",
          "CVE-2026-59138",
          "CVE-2026-61345",
          "CVE-2026-61346",
          "CVE-2026-61347",
          "CVE-2026-61348",
          "CVE-2026-61349",
          "CVE-2026-61350",
          "CVE-2026-61352",
          "CVE-2026-61353",
          "CVE-2026-61355",
          "CVE-2026-61356",
          "CVE-2026-61358",
          "CVE-2026-61359",
          "CVE-2026-61360",
          "CVE-2026-61363",
          "CVE-2026-61364",
          "CVE-2026-61365",
          "CVE-2026-61366",
          "CVE-2026-61367",
          "CVE-2026-61368",
          "CVE-2026-61918",
          "CVE-2026-61921",
          "CVE-2026-61923",
          "CVE-2026-61924",
          "CVE-2026-61925",
          "CVE-2026-61926",
          "CVE-2026-61928",
          "CVE-2026-61929",
          "CVE-2026-61930",
          "CVE-2026-61932",
          "CVE-2026-61934",
          "CVE-2026-61936",
          "CVE-2026-61937",
          "CVE-2026-61939",
          "CVE-2026-62690",
          "CVE-2026-62692",
          "CVE-2026-62695",
          "CVE-2026-62696",
          "CVE-2026-62698",
          "CVE-2026-62699",
          "CVE-2026-62700",
          "CVE-2026-62701",
          "CVE-2026-62702",
          "CVE-2026-62703",
          "CVE-2026-62707",
          "CVE-2026-62709",
          "CVE-2026-62710",
          "CVE-2026-62711",
          "CVE-2026-62712",
          "CVE-2026-62713",
          "CVE-2026-62717",
          "CVE-2026-62719",
          "CVE-2026-62721",
          "CVE-2026-62723",
          "CVE-2026-62724",
          "CVE-2026-62725",
          "CVE-2026-62726",
          "CVE-2026-62727",
          "CVE-2026-62728",
          "CVE-2026-62729",
          "CVE-2026-62730",
          "CVE-2026-62732",
          "CVE-2026-62733",
          "CVE-2026-62734",
          "CVE-2026-62735",
          "CVE-2026-62736",
          "CVE-2026-62738",
          "CVE-2026-62739",
          "CVE-2026-62740",
          "CVE-2026-62741",
          "CVE-2026-62743",
          "CVE-2026-62746",
          "CVE-2026-62747",
          "CVE-2026-62748",
          "CVE-2026-62750",
          "CVE-2026-62751",
          "CVE-2026-62752",
          "CVE-2026-62753",
          "CVE-2026-62755",
          "CVE-2026-62757",
          "CVE-2026-62758",
          "CVE-2026-62768",
          "CVE-2026-62769",
          "CVE-2026-62770",
          "CVE-2026-62771",
          "CVE-2026-62773",
          "CVE-2026-62774",
          "CVE-2026-62777",
          "CVE-2026-62780",
          "CVE-2026-62781",
          "CVE-2026-62782",
          "CVE-2026-62783",
          "CVE-2026-62784",
          "CVE-2026-62785",
          "CVE-2026-62786",
          "CVE-2026-62788",
          "CVE-2026-62790",
          "CVE-2026-62792",
          "CVE-2026-62793",
          "CVE-2026-62795",
          "CVE-2026-62796",
          "CVE-2026-62797",
          "CVE-2026-62798",
          "CVE-2026-62800",
          "CVE-2026-62811",
          "CVE-2026-62815",
          "CVE-2026-62816",
          "CVE-2026-62817",
          "CVE-2026-62819",
          "CVE-2026-62822",
          "CVE-2026-62832",
          "CVE-2026-62876",
          "CVE-2026-62877",
          "CVE-2026-62880",
          "CVE-2026-62881",
          "CVE-2026-62883",
          "CVE-2026-62885",
          "CVE-2026-62887",
          "CVE-2026-62888",
          "CVE-2026-62889",
          "CVE-2026-62890",
          "CVE-2026-62892",
          "CVE-2026-62894",
          "CVE-2026-62908",
          "CVE-2026-65662",
          "CVE-2026-65671",
          "CVE-2026-65672",
          "CVE-2026-65678",
          "CVE-2026-65773",
          "CVE-2026-65774",
          "CVE-2026-65775",
          "CVE-2026-65777",
          "CVE-2026-65784",
          "CVE-2026-65786",
          "CVE-2026-65787",
          "CVE-2026-65788",
          "CVE-2026-65790",
          "CVE-2026-65794",
          "CVE-2026-65795",
          "CVE-2026-65797",
          "CVE-2026-65798",
          "CVE-2026-65799",
          "CVE-2026-65814",
          "CVE-2026-66799",
          "CVE-2026-6726",
          "CVE-2026-6727",
          "CVE-2026-68820",
          "CVE-2026-70304",
          "CVE-2026-70307",
          "CVE-2026-70330",
          "CVE-2026-70344",
          "CVE-2026-70345",
          "CVE-2026-70346",
          "CVE-2026-70347"
        ],
        "details": [
          {
            "id": "CVE-2026-49179",
            "title": "Windows Active Directory Domain Services Remote Code Execution Vulnerability",
            "summary": "Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00831,
            "epssPercentile": 0.55217,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50472",
            "title": "Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54113",
            "title": "Remote Procedure Call Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01126,
            "epssPercentile": 0.64162,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54984",
            "title": "Windows Imaging Component Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.006,
            "epssPercentile": 0.46535,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56174",
            "title": "Windows Narrator Braille Elevation of Privilege Vulnerability",
            "summary": "Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00291,
            "epssPercentile": 0.21293,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59122",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59125",
            "title": "Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability",
            "summary": "Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59126",
            "title": "Windows Event Logging Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59127",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23557,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59128",
            "title": "Windows Encrypting File System (EFS) Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31953,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59130",
            "title": "AMD Zen Information Disclosure Vulnerability",
            "summary": "No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00337,
            "epssPercentile": 0.26512,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59131",
            "title": "AMD Zen Information Disclosure Vulnerability",
            "summary": "No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00284,
            "epssPercentile": 0.20673,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59132",
            "title": "Windows TCP/IP Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01686,
            "epssPercentile": 0.75496,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59134",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00624,
            "epssPercentile": 0.47693,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59135",
            "title": "Microsoft Windows Search Component Information Disclosure Vulnerability",
            "summary": "Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0032,
            "epssPercentile": 0.24552,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59136",
            "title": "Microsoft COM for Windows Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0037,
            "epssPercentile": 0.30138,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59137",
            "title": "Windows Event Logging Service Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31953,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59138",
            "title": "Microsoft Remote Registry Service Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01042,
            "epssPercentile": 0.61833,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61345",
            "title": "Microsoft Remote Registry Service Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01042,
            "epssPercentile": 0.61834,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61346",
            "title": "Windows Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61347",
            "title": "Windows Event Logging Service Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61348",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0159,
            "epssPercentile": 0.7403,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61349",
            "title": "Windows Work Folder Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00238,
            "epssPercentile": 0.14813,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61350",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00449,
            "epssPercentile": 0.3762,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61352",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00428,
            "epssPercentile": 0.35876,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61353",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61355",
            "title": "Windows Sensor Data Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23556,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61356",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61358",
            "title": "Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0368,
            "epssPercentile": 0.88942,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61359",
            "title": "Windows Storage Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00334,
            "epssPercentile": 0.26154,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61360",
            "title": "Windows GDI Information Disclosure Vulnerability",
            "summary": "Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31956,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61363",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00625,
            "epssPercentile": 0.47727,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61364",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61365",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61366",
            "title": "Windows Network Connection Broker Elevation of Privilege Vulnerability",
            "summary": "Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61367",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61368",
            "title": "Windows Hyper-V Information Disclosure Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally.",
            "score": 5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00372,
            "epssPercentile": 0.30393,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61918",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00869,
            "epssPercentile": 0.56428,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61921",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00829,
            "epssPercentile": 0.55174,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61923",
            "title": "Windows Display Enhancement Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61924",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00829,
            "epssPercentile": 0.55173,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61925",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00381,
            "epssPercentile": 0.31232,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61926",
            "title": "Windows USB Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61928",
            "title": "Windows Hello Tampering Vulnerability",
            "summary": "Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0021,
            "epssPercentile": 0.11257,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61929",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01676,
            "epssPercentile": 0.75331,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61930",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02092,
            "epssPercentile": 0.80405,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61932",
            "title": "Windows DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.2356,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61934",
            "title": "Windows Bind Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61936",
            "title": "Windows Defender Firewall Service Security Feature Bypass Vulnerability",
            "summary": "Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00282,
            "epssPercentile": 0.20397,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61937",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61939",
            "title": "Winlogon Elevation of Privilege Vulnerability",
            "summary": "Use after free in Winlogon allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15759,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62690",
            "title": "Windows Push Notifications Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62692",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62695",
            "title": "Windows Storage Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.2356,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62696",
            "title": "Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03401,
            "epssPercentile": 0.88059,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62698",
            "title": "Microsoft Digest Authentication Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00361,
            "epssPercentile": 0.29142,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62699",
            "title": "Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to execute code with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00409,
            "epssPercentile": 0.34136,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62700",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62701",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62702",
            "title": "Windows Graphics Kernel Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00943,
            "epssPercentile": 0.58737,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62703",
            "title": "Windows DWM Core Library Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31954,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62707",
            "title": "Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62709",
            "title": "Windows GDI+ Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31908,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62710",
            "title": "Windows Device Association Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62711",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23518,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62712",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0038,
            "epssPercentile": 0.31158,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62713",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0195,
            "epssPercentile": 0.78893,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62717",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62719",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62721",
            "title": "Windows User-Mode Power Service (UMPS) Elevation of Privilege Vulnerability",
            "summary": "Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0038,
            "epssPercentile": 0.31198,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62723",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62724",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15758,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62725",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09788,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62726",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15758,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62727",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00186,
            "epssPercentile": 0.08256,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62728",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62729",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62730",
            "title": "Windows Wired AutoConfig Service Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62732",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62733",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62734",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62735",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00476,
            "epssPercentile": 0.39473,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62736",
            "title": "Windows DHCP Client Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15004,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62738",
            "title": "Windows Management Instrumentation Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62739",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00249,
            "epssPercentile": 0.1616,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62740",
            "title": "Windows Imaging Component Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31908,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62741",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02092,
            "epssPercentile": 0.80405,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62743",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31954,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62746",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31954,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62747",
            "title": "Windows Device Association Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23557,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62748",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08564,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62750",
            "title": "Windows HTTP Protocol Stack Tampering Vulnerability",
            "summary": "Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00574,
            "epssPercentile": 0.45288,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62751",
            "title": "Windows Projected File System Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23557,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62752",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23556,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62753",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00207,
            "epssPercentile": 0.10799,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62755",
            "title": "Windows DHCP Client Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62757",
            "title": "Windows Schannel Security Feature Bypass Vulnerability",
            "summary": "Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00255,
            "epssPercentile": 0.16929,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62758",
            "title": "Windows Remote Access Connection Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.14966,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62768",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62769",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62770",
            "title": "Windows Shell Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15007,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62771",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00249,
            "epssPercentile": 0.1616,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62773",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09787,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62774",
            "title": "Windows Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09787,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62777",
            "title": "Windows License Manager Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11773,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62780",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10199,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62781",
            "title": "RPC Runtime Library Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00519,
            "epssPercentile": 0.42242,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62782",
            "title": "Windows SMB Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00868,
            "epssPercentile": 0.56396,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62783",
            "title": "Windows Remote Access Connection Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01951,
            "epssPercentile": 0.78901,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62784",
            "title": "Microsoft Local Security Authority Server (lsasrv) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00934,
            "epssPercentile": 0.58442,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62785",
            "title": "Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00837,
            "epssPercentile": 0.55424,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62786",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62788",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26033,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62790",
            "title": "Windows SMBv3 Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00664,
            "epssPercentile": 0.49429,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62792",
            "title": "Windows TCP/IP Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00708,
            "epssPercentile": 0.51162,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62793",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23712,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62795",
            "title": "Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00607,
            "epssPercentile": 0.46873,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62796",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62797",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00334,
            "epssPercentile": 0.26156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62798",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23712,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62800",
            "title": "Windows SMBv3 Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00934,
            "epssPercentile": 0.58442,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62811",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00334,
            "epssPercentile": 0.26156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62815",
            "title": "Microsoft QUIC Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00982,
            "epssPercentile": 0.6,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62816",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00393,
            "epssPercentile": 0.32547,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62817",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00668,
            "epssPercentile": 0.49598,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62819",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00579,
            "epssPercentile": 0.45525,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62822",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00633,
            "epssPercentile": 0.48082,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62832",
            "title": "Windows User Profile Service Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03295,
            "epssPercentile": 0.87687,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62876",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62877",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62880",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15004,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62881",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62883",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17628,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62885",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62887",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22166,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62888",
            "title": "Windows DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01951,
            "epssPercentile": 0.78901,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62889",
            "title": "Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability",
            "summary": "Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0056,
            "epssPercentile": 0.44552,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62890",
            "title": "Windows GDI+ Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00269,
            "epssPercentile": 0.18868,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62892",
            "title": "Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability",
            "summary": "Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09787,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62894",
            "title": "Windows DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00249,
            "epssPercentile": 0.16159,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62908",
            "title": "Windows Backup Engine Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00153,
            "epssPercentile": 0.04738,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65662",
            "title": "Windows GDI Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65671",
            "title": "Remote Access API Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00257,
            "epssPercentile": 0.17266,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65672",
            "title": "Remote Access API Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00257,
            "epssPercentile": 0.17267,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65678",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11662,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65773",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00242,
            "epssPercentile": 0.15314,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65774",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00257,
            "epssPercentile": 0.17266,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65775",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02609,
            "epssPercentile": 0.84381,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65777",
            "title": "Active Directory Security Feature Bypass Vulnerability",
            "summary": "Inadequate encryption strength in Windows Active Directory allows an authorized attacker to bypass a security feature over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00288,
            "epssPercentile": 0.21003,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65784",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00299,
            "epssPercentile": 0.22201,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65786",
            "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65787",
            "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.2356,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65788",
            "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
            "summary": "Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01676,
            "epssPercentile": 0.75331,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65790",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15007,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65794",
            "title": "Windows SMB Client Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00651,
            "epssPercentile": 0.48924,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65795",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17627,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65797",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17582,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65798",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17628,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65799",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00253,
            "epssPercentile": 0.16631,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65814",
            "title": "Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00252,
            "epssPercentile": 0.16578,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66799",
            "title": "Windows Key Guard Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00269,
            "epssPercentile": 0.18868,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-6726",
            "title": "An information leakage vulnerability in the TCG TPM 2.0 reference code.",
            "summary": "An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key. See also TCG VRT0010.",
            "score": 7.9,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00215,
            "epssPercentile": 0.11783,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-6727",
            "title": "CVE-2026-6727",
            "summary": "A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with access to the TPM command interface may be able to exploit timing differences to recover information that could allow decryption of ciphertexts encrypted to TPM-managed RSA keys, including the RSA Endorsement Key (EK), including import blobs, credential blobs, and session salts. Under certain conditi",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00203,
            "epssPercentile": 0.10248,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68820",
            "title": "Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability",
            "summary": "Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2026-08-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.06184,
            "epssPercentile": 0.93023,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2026-08-25 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70304",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00316,
            "epssPercentile": 0.24068,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70307",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00322,
            "epssPercentile": 0.24811,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70330",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00316,
            "epssPercentile": 0.24068,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70344",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70345",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70346",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70347",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23517,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Exploitation reported by the vendor source",
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-62815",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-windows-kb5120242",
      "slug": "microsoft-2026-08-windows-kb5120242",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5120242",
      "title": "Deploy Microsoft Windows security update KB5120242",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5120242",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Windows Server 2022, Windows Server 2022 (Server Core installation)",
      "platform": "Windows",
      "release_version": "10.0.20348.5499",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 195 linked CVEs for Windows Server 2022, Windows Server 2022 (Server Core installation). Microsoft reports exploitation for CVE-2026-68820.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 195,
        "ids": [
          "CVE-2026-42976",
          "CVE-2026-49179",
          "CVE-2026-50472",
          "CVE-2026-54113",
          "CVE-2026-54984",
          "CVE-2026-56174",
          "CVE-2026-59122",
          "CVE-2026-59125",
          "CVE-2026-59126",
          "CVE-2026-59127",
          "CVE-2026-59128",
          "CVE-2026-59130",
          "CVE-2026-59131",
          "CVE-2026-59132",
          "CVE-2026-59134",
          "CVE-2026-59135",
          "CVE-2026-59136",
          "CVE-2026-59137",
          "CVE-2026-59138",
          "CVE-2026-61345",
          "CVE-2026-61346",
          "CVE-2026-61347",
          "CVE-2026-61348",
          "CVE-2026-61349",
          "CVE-2026-61350",
          "CVE-2026-61352",
          "CVE-2026-61353",
          "CVE-2026-61355",
          "CVE-2026-61356",
          "CVE-2026-61358",
          "CVE-2026-61359",
          "CVE-2026-61360",
          "CVE-2026-61363",
          "CVE-2026-61364",
          "CVE-2026-61365",
          "CVE-2026-61366",
          "CVE-2026-61367",
          "CVE-2026-61368",
          "CVE-2026-61918",
          "CVE-2026-61920",
          "CVE-2026-61921",
          "CVE-2026-61923",
          "CVE-2026-61924",
          "CVE-2026-61925",
          "CVE-2026-61926",
          "CVE-2026-61928",
          "CVE-2026-61930",
          "CVE-2026-61932",
          "CVE-2026-61936",
          "CVE-2026-61937",
          "CVE-2026-61939",
          "CVE-2026-62690",
          "CVE-2026-62692",
          "CVE-2026-62695",
          "CVE-2026-62696",
          "CVE-2026-62698",
          "CVE-2026-62699",
          "CVE-2026-62700",
          "CVE-2026-62701",
          "CVE-2026-62702",
          "CVE-2026-62703",
          "CVE-2026-62707",
          "CVE-2026-62709",
          "CVE-2026-62710",
          "CVE-2026-62711",
          "CVE-2026-62712",
          "CVE-2026-62713",
          "CVE-2026-62714",
          "CVE-2026-62715",
          "CVE-2026-62716",
          "CVE-2026-62717",
          "CVE-2026-62718",
          "CVE-2026-62719",
          "CVE-2026-62720",
          "CVE-2026-62721",
          "CVE-2026-62723",
          "CVE-2026-62724",
          "CVE-2026-62725",
          "CVE-2026-62726",
          "CVE-2026-62727",
          "CVE-2026-62728",
          "CVE-2026-62729",
          "CVE-2026-62730",
          "CVE-2026-62732",
          "CVE-2026-62733",
          "CVE-2026-62734",
          "CVE-2026-62735",
          "CVE-2026-62738",
          "CVE-2026-62739",
          "CVE-2026-62740",
          "CVE-2026-62741",
          "CVE-2026-62742",
          "CVE-2026-62743",
          "CVE-2026-62745",
          "CVE-2026-62746",
          "CVE-2026-62747",
          "CVE-2026-62748",
          "CVE-2026-62750",
          "CVE-2026-62751",
          "CVE-2026-62752",
          "CVE-2026-62753",
          "CVE-2026-62754",
          "CVE-2026-62755",
          "CVE-2026-62757",
          "CVE-2026-62758",
          "CVE-2026-62761",
          "CVE-2026-62768",
          "CVE-2026-62769",
          "CVE-2026-62770",
          "CVE-2026-62771",
          "CVE-2026-62773",
          "CVE-2026-62774",
          "CVE-2026-62776",
          "CVE-2026-62777",
          "CVE-2026-62778",
          "CVE-2026-62781",
          "CVE-2026-62782",
          "CVE-2026-62783",
          "CVE-2026-62784",
          "CVE-2026-62785",
          "CVE-2026-62786",
          "CVE-2026-62787",
          "CVE-2026-62790",
          "CVE-2026-62792",
          "CVE-2026-62793",
          "CVE-2026-62795",
          "CVE-2026-62796",
          "CVE-2026-62797",
          "CVE-2026-62800",
          "CVE-2026-62803",
          "CVE-2026-62807",
          "CVE-2026-62811",
          "CVE-2026-62812",
          "CVE-2026-62814",
          "CVE-2026-62815",
          "CVE-2026-62816",
          "CVE-2026-62817",
          "CVE-2026-62818",
          "CVE-2026-62819",
          "CVE-2026-62820",
          "CVE-2026-62822",
          "CVE-2026-62823",
          "CVE-2026-62832",
          "CVE-2026-62876",
          "CVE-2026-62877",
          "CVE-2026-62878",
          "CVE-2026-62880",
          "CVE-2026-62881",
          "CVE-2026-62883",
          "CVE-2026-62885",
          "CVE-2026-62887",
          "CVE-2026-62888",
          "CVE-2026-62889",
          "CVE-2026-62890",
          "CVE-2026-62892",
          "CVE-2026-62893",
          "CVE-2026-62894",
          "CVE-2026-62908",
          "CVE-2026-65662",
          "CVE-2026-65671",
          "CVE-2026-65672",
          "CVE-2026-65678",
          "CVE-2026-65679",
          "CVE-2026-65681",
          "CVE-2026-65773",
          "CVE-2026-65774",
          "CVE-2026-65775",
          "CVE-2026-65777",
          "CVE-2026-65784",
          "CVE-2026-65786",
          "CVE-2026-65787",
          "CVE-2026-65789",
          "CVE-2026-65790",
          "CVE-2026-65791",
          "CVE-2026-65794",
          "CVE-2026-65795",
          "CVE-2026-65796",
          "CVE-2026-65797",
          "CVE-2026-65798",
          "CVE-2026-65799",
          "CVE-2026-65814",
          "CVE-2026-66799",
          "CVE-2026-66802",
          "CVE-2026-6726",
          "CVE-2026-6727",
          "CVE-2026-68819",
          "CVE-2026-68820",
          "CVE-2026-70304",
          "CVE-2026-70307",
          "CVE-2026-70330",
          "CVE-2026-70344",
          "CVE-2026-70345",
          "CVE-2026-70346",
          "CVE-2026-70347",
          "CVE-2026-71331"
        ],
        "details": [
          {
            "id": "CVE-2026-42976",
            "title": "Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11772,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49179",
            "title": "Windows Active Directory Domain Services Remote Code Execution Vulnerability",
            "summary": "Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00831,
            "epssPercentile": 0.55217,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50472",
            "title": "Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54113",
            "title": "Remote Procedure Call Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01126,
            "epssPercentile": 0.64162,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54984",
            "title": "Windows Imaging Component Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.006,
            "epssPercentile": 0.46535,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56174",
            "title": "Windows Narrator Braille Elevation of Privilege Vulnerability",
            "summary": "Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00291,
            "epssPercentile": 0.21293,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59122",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59125",
            "title": "Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability",
            "summary": "Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59126",
            "title": "Windows Event Logging Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59127",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23557,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59128",
            "title": "Windows Encrypting File System (EFS) Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31953,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59130",
            "title": "AMD Zen Information Disclosure Vulnerability",
            "summary": "No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00337,
            "epssPercentile": 0.26512,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59131",
            "title": "AMD Zen Information Disclosure Vulnerability",
            "summary": "No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00284,
            "epssPercentile": 0.20673,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59132",
            "title": "Windows TCP/IP Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01686,
            "epssPercentile": 0.75496,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59134",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00624,
            "epssPercentile": 0.47693,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59135",
            "title": "Microsoft Windows Search Component Information Disclosure Vulnerability",
            "summary": "Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0032,
            "epssPercentile": 0.24552,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59136",
            "title": "Microsoft COM for Windows Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0037,
            "epssPercentile": 0.30138,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59137",
            "title": "Windows Event Logging Service Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31953,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59138",
            "title": "Microsoft Remote Registry Service Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01042,
            "epssPercentile": 0.61833,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61345",
            "title": "Microsoft Remote Registry Service Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01042,
            "epssPercentile": 0.61834,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61346",
            "title": "Windows Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61347",
            "title": "Windows Event Logging Service Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61348",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0159,
            "epssPercentile": 0.7403,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61349",
            "title": "Windows Work Folder Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00238,
            "epssPercentile": 0.14813,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61350",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00449,
            "epssPercentile": 0.3762,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61352",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00428,
            "epssPercentile": 0.35876,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61353",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61355",
            "title": "Windows Sensor Data Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23556,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61356",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61358",
            "title": "Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0368,
            "epssPercentile": 0.88942,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61359",
            "title": "Windows Storage Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00334,
            "epssPercentile": 0.26154,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61360",
            "title": "Windows GDI Information Disclosure Vulnerability",
            "summary": "Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31956,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61363",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00625,
            "epssPercentile": 0.47727,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61364",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61365",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61366",
            "title": "Windows Network Connection Broker Elevation of Privilege Vulnerability",
            "summary": "Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61367",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61368",
            "title": "Windows Hyper-V Information Disclosure Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally.",
            "score": 5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00372,
            "epssPercentile": 0.30393,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61918",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00869,
            "epssPercentile": 0.56428,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61920",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a network.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00484,
            "epssPercentile": 0.39993,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61921",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00829,
            "epssPercentile": 0.55174,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61923",
            "title": "Windows Display Enhancement Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61924",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00829,
            "epssPercentile": 0.55173,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61925",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00381,
            "epssPercentile": 0.31232,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61926",
            "title": "Windows USB Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61928",
            "title": "Windows Hello Tampering Vulnerability",
            "summary": "Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0021,
            "epssPercentile": 0.11257,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61930",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02092,
            "epssPercentile": 0.80405,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61932",
            "title": "Windows DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.2356,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61936",
            "title": "Windows Defender Firewall Service Security Feature Bypass Vulnerability",
            "summary": "Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00282,
            "epssPercentile": 0.20397,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61937",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61939",
            "title": "Winlogon Elevation of Privilege Vulnerability",
            "summary": "Use after free in Winlogon allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15759,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62690",
            "title": "Windows Push Notifications Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62692",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62695",
            "title": "Windows Storage Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.2356,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62696",
            "title": "Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03401,
            "epssPercentile": 0.88059,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62698",
            "title": "Microsoft Digest Authentication Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00361,
            "epssPercentile": 0.29142,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62699",
            "title": "Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to execute code with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00409,
            "epssPercentile": 0.34136,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62700",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62701",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62702",
            "title": "Windows Graphics Kernel Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00943,
            "epssPercentile": 0.58737,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62703",
            "title": "Windows DWM Core Library Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31954,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62707",
            "title": "Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62709",
            "title": "Windows GDI+ Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31908,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62710",
            "title": "Windows Device Association Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62711",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23518,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62712",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0038,
            "epssPercentile": 0.31158,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62713",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0195,
            "epssPercentile": 0.78893,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62714",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00468,
            "epssPercentile": 0.3888,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62715",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0048,
            "epssPercentile": 0.3977,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62716",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00468,
            "epssPercentile": 0.3888,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62717",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62718",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0048,
            "epssPercentile": 0.39771,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62719",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62720",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00468,
            "epssPercentile": 0.3888,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62721",
            "title": "Windows User-Mode Power Service (UMPS) Elevation of Privilege Vulnerability",
            "summary": "Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0038,
            "epssPercentile": 0.31198,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62723",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62724",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15758,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62725",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09788,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62726",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15758,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62727",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00186,
            "epssPercentile": 0.08256,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62728",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62729",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62730",
            "title": "Windows Wired AutoConfig Service Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62732",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62733",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62734",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62735",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00476,
            "epssPercentile": 0.39473,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62738",
            "title": "Windows Management Instrumentation Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62739",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00249,
            "epssPercentile": 0.1616,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62740",
            "title": "Windows Imaging Component Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31908,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62741",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02092,
            "epssPercentile": 0.80405,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62742",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0048,
            "epssPercentile": 0.39771,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62743",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31954,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62745",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00361,
            "epssPercentile": 0.29156,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62746",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31954,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62747",
            "title": "Windows Device Association Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23557,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62748",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08564,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62750",
            "title": "Windows HTTP Protocol Stack Tampering Vulnerability",
            "summary": "Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00574,
            "epssPercentile": 0.45288,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62751",
            "title": "Windows Projected File System Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23557,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62752",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23556,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62753",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00207,
            "epssPercentile": 0.10799,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62754",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62755",
            "title": "Windows DHCP Client Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62757",
            "title": "Windows Schannel Security Feature Bypass Vulnerability",
            "summary": "Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00255,
            "epssPercentile": 0.16929,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62758",
            "title": "Windows Remote Access Connection Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.14966,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62761",
            "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00355,
            "epssPercentile": 0.28559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62768",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62769",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62770",
            "title": "Windows Shell Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15007,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62771",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00249,
            "epssPercentile": 0.1616,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62773",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09787,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62774",
            "title": "Windows Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09787,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62776",
            "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00271,
            "epssPercentile": 0.19237,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62777",
            "title": "Windows License Manager Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11773,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62778",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00506,
            "epssPercentile": 0.41401,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62781",
            "title": "RPC Runtime Library Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00519,
            "epssPercentile": 0.42242,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62782",
            "title": "Windows SMB Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00868,
            "epssPercentile": 0.56396,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62783",
            "title": "Windows Remote Access Connection Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01951,
            "epssPercentile": 0.78901,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62784",
            "title": "Microsoft Local Security Authority Server (lsasrv) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00934,
            "epssPercentile": 0.58442,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62785",
            "title": "Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00837,
            "epssPercentile": 0.55424,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62786",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62787",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows DNS allows an authorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0053,
            "epssPercentile": 0.4292,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62790",
            "title": "Windows SMBv3 Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00664,
            "epssPercentile": 0.49429,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62792",
            "title": "Windows TCP/IP Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00708,
            "epssPercentile": 0.51162,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62793",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23712,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62795",
            "title": "Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00607,
            "epssPercentile": 0.46873,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62796",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62797",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00334,
            "epssPercentile": 0.26156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62800",
            "title": "Windows SMBv3 Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00934,
            "epssPercentile": 0.58442,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62803",
            "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00371,
            "epssPercentile": 0.30191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62807",
            "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00371,
            "epssPercentile": 0.30191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62811",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00334,
            "epssPercentile": 0.26156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62812",
            "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00291,
            "epssPercentile": 0.21362,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62814",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00537,
            "epssPercentile": 0.43342,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62815",
            "title": "Microsoft QUIC Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00982,
            "epssPercentile": 0.6,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62816",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00393,
            "epssPercentile": 0.32547,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62817",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00668,
            "epssPercentile": 0.49598,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62818",
            "title": "Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability",
            "summary": "Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00972,
            "epssPercentile": 0.59701,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62819",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00579,
            "epssPercentile": 0.45525,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62820",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00543,
            "epssPercentile": 0.43643,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62822",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00633,
            "epssPercentile": 0.48082,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62823",
            "title": "Windows DHCP Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00662,
            "epssPercentile": 0.49371,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62832",
            "title": "Windows User Profile Service Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03295,
            "epssPercentile": 0.87687,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62876",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62877",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62878",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0126,
            "epssPercentile": 0.67668,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62880",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15004,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62881",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62883",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17628,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62885",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62887",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22166,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62888",
            "title": "Windows DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01951,
            "epssPercentile": 0.78901,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62889",
            "title": "Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability",
            "summary": "Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0056,
            "epssPercentile": 0.44552,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62890",
            "title": "Windows GDI+ Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00269,
            "epssPercentile": 0.18868,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62892",
            "title": "Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability",
            "summary": "Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09787,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62893",
            "title": "Windows Deployment Services TFTP Server Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02732,
            "epssPercentile": 0.85128,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62894",
            "title": "Windows DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00249,
            "epssPercentile": 0.16159,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62908",
            "title": "Windows Backup Engine Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00153,
            "epssPercentile": 0.04738,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65662",
            "title": "Windows GDI Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65671",
            "title": "Remote Access API Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00257,
            "epssPercentile": 0.17266,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65672",
            "title": "Remote Access API Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00257,
            "epssPercentile": 0.17267,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65678",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11662,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65679",
            "title": "Windows iSCSI Target Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00566,
            "epssPercentile": 0.44906,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65681",
            "title": "Windows iSCSI Target Service Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00886,
            "epssPercentile": 0.56926,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65773",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00242,
            "epssPercentile": 0.15314,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65774",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00257,
            "epssPercentile": 0.17266,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65775",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02609,
            "epssPercentile": 0.84381,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65777",
            "title": "Active Directory Security Feature Bypass Vulnerability",
            "summary": "Inadequate encryption strength in Windows Active Directory allows an authorized attacker to bypass a security feature over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00288,
            "epssPercentile": 0.21003,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65784",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00299,
            "epssPercentile": 0.22201,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65786",
            "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65787",
            "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.2356,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65789",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00544,
            "epssPercentile": 0.43722,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65790",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15007,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65791",
            "title": "Windows iSCSI Target Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.006,
            "epssPercentile": 0.46555,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65794",
            "title": "Windows SMB Client Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00651,
            "epssPercentile": 0.48924,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65795",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17627,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65796",
            "title": "Windows iSCSI Target Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00528,
            "epssPercentile": 0.42787,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65797",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17582,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65798",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17628,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65799",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00253,
            "epssPercentile": 0.16631,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65814",
            "title": "Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00252,
            "epssPercentile": 0.16578,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66799",
            "title": "Windows Key Guard Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00269,
            "epssPercentile": 0.18868,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66802",
            "title": "Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0036,
            "epssPercentile": 0.29053,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-6726",
            "title": "An information leakage vulnerability in the TCG TPM 2.0 reference code.",
            "summary": "An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key. See also TCG VRT0010.",
            "score": 7.9,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00215,
            "epssPercentile": 0.11783,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-6727",
            "title": "CVE-2026-6727",
            "summary": "A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with access to the TPM command interface may be able to exploit timing differences to recover information that could allow decryption of ciphertexts encrypted to TPM-managed RSA keys, including the RSA Endorsement Key (EK), including import blobs, credential blobs, and session salts. Under certain conditi",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00203,
            "epssPercentile": 0.10248,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68819",
            "title": "Windows Network File System Denial of Service Vulnerability",
            "summary": "Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00684,
            "epssPercentile": 0.50268,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68820",
            "title": "Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability",
            "summary": "Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2026-08-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.06184,
            "epssPercentile": 0.93023,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2026-08-25 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70304",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00316,
            "epssPercentile": 0.24068,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70307",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00322,
            "epssPercentile": 0.24811,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70330",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00316,
            "epssPercentile": 0.24068,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70344",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70345",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70346",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70347",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23517,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-71331",
            "title": "Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00454,
            "epssPercentile": 0.37968,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Exploitation reported by the vendor source",
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-65791",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-windows-kb5120249",
      "slug": "microsoft-2026-08-windows-kb5120249",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5120249",
      "title": "Deploy Microsoft Windows security update KB5120249",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5120249",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems",
      "platform": "Windows",
      "release_version": "10.0.19044.7663",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 160 linked CVEs for Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems. Microsoft reports exploitation for CVE-2026-68820.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 160,
        "ids": [
          "CVE-2026-42976",
          "CVE-2026-49179",
          "CVE-2026-50472",
          "CVE-2026-54113",
          "CVE-2026-54984",
          "CVE-2026-56174",
          "CVE-2026-59122",
          "CVE-2026-59125",
          "CVE-2026-59126",
          "CVE-2026-59127",
          "CVE-2026-59128",
          "CVE-2026-59130",
          "CVE-2026-59131",
          "CVE-2026-59132",
          "CVE-2026-59134",
          "CVE-2026-59135",
          "CVE-2026-59136",
          "CVE-2026-59137",
          "CVE-2026-59138",
          "CVE-2026-61345",
          "CVE-2026-61346",
          "CVE-2026-61347",
          "CVE-2026-61348",
          "CVE-2026-61349",
          "CVE-2026-61350",
          "CVE-2026-61352",
          "CVE-2026-61353",
          "CVE-2026-61355",
          "CVE-2026-61356",
          "CVE-2026-61358",
          "CVE-2026-61360",
          "CVE-2026-61363",
          "CVE-2026-61364",
          "CVE-2026-61365",
          "CVE-2026-61366",
          "CVE-2026-61367",
          "CVE-2026-61368",
          "CVE-2026-61918",
          "CVE-2026-61921",
          "CVE-2026-61923",
          "CVE-2026-61924",
          "CVE-2026-61925",
          "CVE-2026-61926",
          "CVE-2026-61928",
          "CVE-2026-61930",
          "CVE-2026-61932",
          "CVE-2026-61936",
          "CVE-2026-61937",
          "CVE-2026-61939",
          "CVE-2026-62690",
          "CVE-2026-62692",
          "CVE-2026-62696",
          "CVE-2026-62698",
          "CVE-2026-62699",
          "CVE-2026-62700",
          "CVE-2026-62701",
          "CVE-2026-62702",
          "CVE-2026-62703",
          "CVE-2026-62707",
          "CVE-2026-62709",
          "CVE-2026-62710",
          "CVE-2026-62711",
          "CVE-2026-62712",
          "CVE-2026-62713",
          "CVE-2026-62717",
          "CVE-2026-62719",
          "CVE-2026-62721",
          "CVE-2026-62723",
          "CVE-2026-62724",
          "CVE-2026-62725",
          "CVE-2026-62726",
          "CVE-2026-62727",
          "CVE-2026-62728",
          "CVE-2026-62729",
          "CVE-2026-62730",
          "CVE-2026-62732",
          "CVE-2026-62733",
          "CVE-2026-62734",
          "CVE-2026-62735",
          "CVE-2026-62738",
          "CVE-2026-62739",
          "CVE-2026-62740",
          "CVE-2026-62741",
          "CVE-2026-62743",
          "CVE-2026-62746",
          "CVE-2026-62747",
          "CVE-2026-62748",
          "CVE-2026-62750",
          "CVE-2026-62751",
          "CVE-2026-62752",
          "CVE-2026-62753",
          "CVE-2026-62754",
          "CVE-2026-62755",
          "CVE-2026-62757",
          "CVE-2026-62758",
          "CVE-2026-62768",
          "CVE-2026-62769",
          "CVE-2026-62770",
          "CVE-2026-62771",
          "CVE-2026-62773",
          "CVE-2026-62774",
          "CVE-2026-62777",
          "CVE-2026-62781",
          "CVE-2026-62782",
          "CVE-2026-62783",
          "CVE-2026-62784",
          "CVE-2026-62785",
          "CVE-2026-62786",
          "CVE-2026-62790",
          "CVE-2026-62792",
          "CVE-2026-62793",
          "CVE-2026-62795",
          "CVE-2026-62796",
          "CVE-2026-62797",
          "CVE-2026-62800",
          "CVE-2026-62816",
          "CVE-2026-62817",
          "CVE-2026-62819",
          "CVE-2026-62822",
          "CVE-2026-62832",
          "CVE-2026-62876",
          "CVE-2026-62877",
          "CVE-2026-62880",
          "CVE-2026-62881",
          "CVE-2026-62883",
          "CVE-2026-62885",
          "CVE-2026-62887",
          "CVE-2026-62888",
          "CVE-2026-62889",
          "CVE-2026-62890",
          "CVE-2026-62892",
          "CVE-2026-62894",
          "CVE-2026-62908",
          "CVE-2026-65662",
          "CVE-2026-65671",
          "CVE-2026-65678",
          "CVE-2026-65773",
          "CVE-2026-65774",
          "CVE-2026-65775",
          "CVE-2026-65784",
          "CVE-2026-65786",
          "CVE-2026-65787",
          "CVE-2026-65790",
          "CVE-2026-65794",
          "CVE-2026-65795",
          "CVE-2026-65797",
          "CVE-2026-65798",
          "CVE-2026-65799",
          "CVE-2026-65814",
          "CVE-2026-66799",
          "CVE-2026-6726",
          "CVE-2026-6727",
          "CVE-2026-68820",
          "CVE-2026-70304",
          "CVE-2026-70307",
          "CVE-2026-70330",
          "CVE-2026-70344",
          "CVE-2026-70345",
          "CVE-2026-70346",
          "CVE-2026-70347"
        ],
        "details": [
          {
            "id": "CVE-2026-42976",
            "title": "Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11772,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49179",
            "title": "Windows Active Directory Domain Services Remote Code Execution Vulnerability",
            "summary": "Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00831,
            "epssPercentile": 0.55217,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50472",
            "title": "Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54113",
            "title": "Remote Procedure Call Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01126,
            "epssPercentile": 0.64162,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54984",
            "title": "Windows Imaging Component Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.006,
            "epssPercentile": 0.46535,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56174",
            "title": "Windows Narrator Braille Elevation of Privilege Vulnerability",
            "summary": "Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00291,
            "epssPercentile": 0.21293,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59122",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59125",
            "title": "Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability",
            "summary": "Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59126",
            "title": "Windows Event Logging Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59127",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23557,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59128",
            "title": "Windows Encrypting File System (EFS) Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31953,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59130",
            "title": "AMD Zen Information Disclosure Vulnerability",
            "summary": "No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00337,
            "epssPercentile": 0.26512,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59131",
            "title": "AMD Zen Information Disclosure Vulnerability",
            "summary": "No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00284,
            "epssPercentile": 0.20673,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59132",
            "title": "Windows TCP/IP Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01686,
            "epssPercentile": 0.75496,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59134",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00624,
            "epssPercentile": 0.47693,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59135",
            "title": "Microsoft Windows Search Component Information Disclosure Vulnerability",
            "summary": "Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0032,
            "epssPercentile": 0.24552,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59136",
            "title": "Microsoft COM for Windows Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0037,
            "epssPercentile": 0.30138,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59137",
            "title": "Windows Event Logging Service Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31953,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59138",
            "title": "Microsoft Remote Registry Service Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01042,
            "epssPercentile": 0.61833,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61345",
            "title": "Microsoft Remote Registry Service Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01042,
            "epssPercentile": 0.61834,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61346",
            "title": "Windows Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61347",
            "title": "Windows Event Logging Service Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61348",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0159,
            "epssPercentile": 0.7403,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61349",
            "title": "Windows Work Folder Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00238,
            "epssPercentile": 0.14813,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61350",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00449,
            "epssPercentile": 0.3762,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61352",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00428,
            "epssPercentile": 0.35876,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61353",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61355",
            "title": "Windows Sensor Data Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23556,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61356",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61358",
            "title": "Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0368,
            "epssPercentile": 0.88942,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61360",
            "title": "Windows GDI Information Disclosure Vulnerability",
            "summary": "Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31956,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61363",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00625,
            "epssPercentile": 0.47727,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61364",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61365",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61366",
            "title": "Windows Network Connection Broker Elevation of Privilege Vulnerability",
            "summary": "Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61367",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61368",
            "title": "Windows Hyper-V Information Disclosure Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally.",
            "score": 5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00372,
            "epssPercentile": 0.30393,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61918",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00869,
            "epssPercentile": 0.56428,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61921",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00829,
            "epssPercentile": 0.55174,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61923",
            "title": "Windows Display Enhancement Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61924",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00829,
            "epssPercentile": 0.55173,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61925",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00381,
            "epssPercentile": 0.31232,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61926",
            "title": "Windows USB Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61928",
            "title": "Windows Hello Tampering Vulnerability",
            "summary": "Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0021,
            "epssPercentile": 0.11257,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61930",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02092,
            "epssPercentile": 0.80405,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61932",
            "title": "Windows DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.2356,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61936",
            "title": "Windows Defender Firewall Service Security Feature Bypass Vulnerability",
            "summary": "Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00282,
            "epssPercentile": 0.20397,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61937",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61939",
            "title": "Winlogon Elevation of Privilege Vulnerability",
            "summary": "Use after free in Winlogon allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15759,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62690",
            "title": "Windows Push Notifications Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62692",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62696",
            "title": "Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03401,
            "epssPercentile": 0.88059,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62698",
            "title": "Microsoft Digest Authentication Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00361,
            "epssPercentile": 0.29142,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62699",
            "title": "Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to execute code with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00409,
            "epssPercentile": 0.34136,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62700",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62701",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62702",
            "title": "Windows Graphics Kernel Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00943,
            "epssPercentile": 0.58737,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62703",
            "title": "Windows DWM Core Library Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31954,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62707",
            "title": "Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62709",
            "title": "Windows GDI+ Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31908,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62710",
            "title": "Windows Device Association Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62711",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23518,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62712",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0038,
            "epssPercentile": 0.31158,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62713",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0195,
            "epssPercentile": 0.78893,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62717",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62719",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62721",
            "title": "Windows User-Mode Power Service (UMPS) Elevation of Privilege Vulnerability",
            "summary": "Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0038,
            "epssPercentile": 0.31198,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62723",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62724",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15758,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62725",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09788,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62726",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15758,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62727",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00186,
            "epssPercentile": 0.08256,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62728",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62729",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62730",
            "title": "Windows Wired AutoConfig Service Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62732",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62733",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62734",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62735",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00476,
            "epssPercentile": 0.39473,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62738",
            "title": "Windows Management Instrumentation Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62739",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00249,
            "epssPercentile": 0.1616,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62740",
            "title": "Windows Imaging Component Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31908,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62741",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02092,
            "epssPercentile": 0.80405,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62743",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31954,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62746",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31954,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62747",
            "title": "Windows Device Association Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23557,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62748",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08564,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62750",
            "title": "Windows HTTP Protocol Stack Tampering Vulnerability",
            "summary": "Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00574,
            "epssPercentile": 0.45288,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62751",
            "title": "Windows Projected File System Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23557,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62752",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23556,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62753",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00207,
            "epssPercentile": 0.10799,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62754",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62755",
            "title": "Windows DHCP Client Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62757",
            "title": "Windows Schannel Security Feature Bypass Vulnerability",
            "summary": "Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00255,
            "epssPercentile": 0.16929,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62758",
            "title": "Windows Remote Access Connection Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.14966,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62768",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62769",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62770",
            "title": "Windows Shell Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15007,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62771",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00249,
            "epssPercentile": 0.1616,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62773",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09787,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62774",
            "title": "Windows Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09787,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62777",
            "title": "Windows License Manager Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11773,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62781",
            "title": "RPC Runtime Library Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00519,
            "epssPercentile": 0.42242,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62782",
            "title": "Windows SMB Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00868,
            "epssPercentile": 0.56396,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62783",
            "title": "Windows Remote Access Connection Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01951,
            "epssPercentile": 0.78901,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62784",
            "title": "Microsoft Local Security Authority Server (lsasrv) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00934,
            "epssPercentile": 0.58442,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62785",
            "title": "Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00837,
            "epssPercentile": 0.55424,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62786",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62790",
            "title": "Windows SMBv3 Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00664,
            "epssPercentile": 0.49429,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62792",
            "title": "Windows TCP/IP Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00708,
            "epssPercentile": 0.51162,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62793",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23712,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62795",
            "title": "Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00607,
            "epssPercentile": 0.46873,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62796",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62797",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00334,
            "epssPercentile": 0.26156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62800",
            "title": "Windows SMBv3 Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00934,
            "epssPercentile": 0.58442,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62816",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00393,
            "epssPercentile": 0.32547,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62817",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00668,
            "epssPercentile": 0.49598,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62819",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00579,
            "epssPercentile": 0.45525,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62822",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00633,
            "epssPercentile": 0.48082,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62832",
            "title": "Windows User Profile Service Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03295,
            "epssPercentile": 0.87687,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62876",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62877",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62880",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15004,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62881",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62883",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17628,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62885",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62887",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22166,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62888",
            "title": "Windows DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01951,
            "epssPercentile": 0.78901,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62889",
            "title": "Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability",
            "summary": "Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0056,
            "epssPercentile": 0.44552,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62890",
            "title": "Windows GDI+ Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00269,
            "epssPercentile": 0.18868,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62892",
            "title": "Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability",
            "summary": "Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09787,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62894",
            "title": "Windows DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00249,
            "epssPercentile": 0.16159,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62908",
            "title": "Windows Backup Engine Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00153,
            "epssPercentile": 0.04738,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65662",
            "title": "Windows GDI Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65671",
            "title": "Remote Access API Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00257,
            "epssPercentile": 0.17266,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65678",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11662,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65773",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00242,
            "epssPercentile": 0.15314,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65774",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00257,
            "epssPercentile": 0.17266,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65775",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02609,
            "epssPercentile": 0.84381,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65784",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00299,
            "epssPercentile": 0.22201,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65786",
            "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65787",
            "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.2356,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65790",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15007,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65794",
            "title": "Windows SMB Client Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00651,
            "epssPercentile": 0.48924,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65795",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17627,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65797",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17582,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65798",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17628,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65799",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00253,
            "epssPercentile": 0.16631,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65814",
            "title": "Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00252,
            "epssPercentile": 0.16578,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66799",
            "title": "Windows Key Guard Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00269,
            "epssPercentile": 0.18868,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-6726",
            "title": "An information leakage vulnerability in the TCG TPM 2.0 reference code.",
            "summary": "An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key. See also TCG VRT0010.",
            "score": 7.9,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00215,
            "epssPercentile": 0.11783,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-6727",
            "title": "CVE-2026-6727",
            "summary": "A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with access to the TPM command interface may be able to exploit timing differences to recover information that could allow decryption of ciphertexts encrypted to TPM-managed RSA keys, including the RSA Endorsement Key (EK), including import blobs, credential blobs, and session salts. Under certain conditi",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00203,
            "epssPercentile": 0.10248,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68820",
            "title": "Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability",
            "summary": "Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2026-08-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.06184,
            "epssPercentile": 0.93023,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2026-08-25 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70304",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00316,
            "epssPercentile": 0.24068,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70307",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00322,
            "epssPercentile": 0.24811,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70330",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00316,
            "epssPercentile": 0.24068,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70344",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70345",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70346",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70347",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23517,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Exploitation reported by the vendor source",
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-62822",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-windows-kb5120418",
      "slug": "microsoft-2026-08-windows-kb5120418",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5120418",
      "title": "Deploy Microsoft Windows security update KB5120418",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5120418",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Windows 10 Version 1607 for 32-bit Systems, Windows 10 Version 1607 for x64-based Systems, Windows Server 2016, plus 1 more",
      "platform": "Windows",
      "release_version": "10.0.14393.9418",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 167 linked CVEs for Windows 10 Version 1607 for 32-bit Systems, Windows 10 Version 1607 for x64-based Systems, Windows Server 2016, plus 1 more. Microsoft reports exploitation for CVE-2026-68820.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 167,
        "ids": [
          "CVE-2026-42976",
          "CVE-2026-49179",
          "CVE-2026-50472",
          "CVE-2026-54113",
          "CVE-2026-54984",
          "CVE-2026-59122",
          "CVE-2026-59125",
          "CVE-2026-59127",
          "CVE-2026-59128",
          "CVE-2026-59130",
          "CVE-2026-59131",
          "CVE-2026-59132",
          "CVE-2026-59134",
          "CVE-2026-59135",
          "CVE-2026-59136",
          "CVE-2026-59137",
          "CVE-2026-59138",
          "CVE-2026-61345",
          "CVE-2026-61347",
          "CVE-2026-61348",
          "CVE-2026-61349",
          "CVE-2026-61350",
          "CVE-2026-61352",
          "CVE-2026-61353",
          "CVE-2026-61360",
          "CVE-2026-61363",
          "CVE-2026-61364",
          "CVE-2026-61365",
          "CVE-2026-61366",
          "CVE-2026-61367",
          "CVE-2026-61368",
          "CVE-2026-61918",
          "CVE-2026-61920",
          "CVE-2026-61921",
          "CVE-2026-61924",
          "CVE-2026-61925",
          "CVE-2026-61926",
          "CVE-2026-61928",
          "CVE-2026-61930",
          "CVE-2026-61932",
          "CVE-2026-61937",
          "CVE-2026-61939",
          "CVE-2026-62692",
          "CVE-2026-62696",
          "CVE-2026-62698",
          "CVE-2026-62699",
          "CVE-2026-62700",
          "CVE-2026-62701",
          "CVE-2026-62707",
          "CVE-2026-62709",
          "CVE-2026-62710",
          "CVE-2026-62711",
          "CVE-2026-62712",
          "CVE-2026-62714",
          "CVE-2026-62715",
          "CVE-2026-62716",
          "CVE-2026-62717",
          "CVE-2026-62718",
          "CVE-2026-62719",
          "CVE-2026-62720",
          "CVE-2026-62721",
          "CVE-2026-62723",
          "CVE-2026-62724",
          "CVE-2026-62725",
          "CVE-2026-62726",
          "CVE-2026-62727",
          "CVE-2026-62728",
          "CVE-2026-62729",
          "CVE-2026-62730",
          "CVE-2026-62732",
          "CVE-2026-62733",
          "CVE-2026-62734",
          "CVE-2026-62735",
          "CVE-2026-62738",
          "CVE-2026-62740",
          "CVE-2026-62741",
          "CVE-2026-62742",
          "CVE-2026-62743",
          "CVE-2026-62745",
          "CVE-2026-62746",
          "CVE-2026-62747",
          "CVE-2026-62748",
          "CVE-2026-62750",
          "CVE-2026-62752",
          "CVE-2026-62753",
          "CVE-2026-62754",
          "CVE-2026-62755",
          "CVE-2026-62757",
          "CVE-2026-62758",
          "CVE-2026-62761",
          "CVE-2026-62768",
          "CVE-2026-62769",
          "CVE-2026-62770",
          "CVE-2026-62773",
          "CVE-2026-62774",
          "CVE-2026-62776",
          "CVE-2026-62777",
          "CVE-2026-62778",
          "CVE-2026-62781",
          "CVE-2026-62782",
          "CVE-2026-62784",
          "CVE-2026-62785",
          "CVE-2026-62786",
          "CVE-2026-62787",
          "CVE-2026-62790",
          "CVE-2026-62792",
          "CVE-2026-62793",
          "CVE-2026-62795",
          "CVE-2026-62796",
          "CVE-2026-62797",
          "CVE-2026-62800",
          "CVE-2026-62803",
          "CVE-2026-62807",
          "CVE-2026-62812",
          "CVE-2026-62814",
          "CVE-2026-62816",
          "CVE-2026-62818",
          "CVE-2026-62819",
          "CVE-2026-62820",
          "CVE-2026-62822",
          "CVE-2026-62823",
          "CVE-2026-62824",
          "CVE-2026-62876",
          "CVE-2026-62877",
          "CVE-2026-62878",
          "CVE-2026-62880",
          "CVE-2026-62881",
          "CVE-2026-62883",
          "CVE-2026-62885",
          "CVE-2026-62887",
          "CVE-2026-62889",
          "CVE-2026-62890",
          "CVE-2026-62893",
          "CVE-2026-62894",
          "CVE-2026-62908",
          "CVE-2026-65662",
          "CVE-2026-65671",
          "CVE-2026-65678",
          "CVE-2026-65679",
          "CVE-2026-65681",
          "CVE-2026-65774",
          "CVE-2026-65775",
          "CVE-2026-65784",
          "CVE-2026-65786",
          "CVE-2026-65787",
          "CVE-2026-65789",
          "CVE-2026-65790",
          "CVE-2026-65791",
          "CVE-2026-65794",
          "CVE-2026-65795",
          "CVE-2026-65796",
          "CVE-2026-65797",
          "CVE-2026-65798",
          "CVE-2026-65799",
          "CVE-2026-65814",
          "CVE-2026-66799",
          "CVE-2026-6726",
          "CVE-2026-6727",
          "CVE-2026-68819",
          "CVE-2026-68820",
          "CVE-2026-70304",
          "CVE-2026-70307",
          "CVE-2026-70330",
          "CVE-2026-70344",
          "CVE-2026-70345",
          "CVE-2026-70346",
          "CVE-2026-70347"
        ],
        "details": [
          {
            "id": "CVE-2026-42976",
            "title": "Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11772,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49179",
            "title": "Windows Active Directory Domain Services Remote Code Execution Vulnerability",
            "summary": "Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00831,
            "epssPercentile": 0.55217,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50472",
            "title": "Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54113",
            "title": "Remote Procedure Call Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01126,
            "epssPercentile": 0.64162,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54984",
            "title": "Windows Imaging Component Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.006,
            "epssPercentile": 0.46535,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59122",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59125",
            "title": "Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability",
            "summary": "Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59127",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23557,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59128",
            "title": "Windows Encrypting File System (EFS) Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31953,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59130",
            "title": "AMD Zen Information Disclosure Vulnerability",
            "summary": "No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00337,
            "epssPercentile": 0.26512,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59131",
            "title": "AMD Zen Information Disclosure Vulnerability",
            "summary": "No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00284,
            "epssPercentile": 0.20673,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59132",
            "title": "Windows TCP/IP Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01686,
            "epssPercentile": 0.75496,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59134",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00624,
            "epssPercentile": 0.47693,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59135",
            "title": "Microsoft Windows Search Component Information Disclosure Vulnerability",
            "summary": "Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0032,
            "epssPercentile": 0.24552,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59136",
            "title": "Microsoft COM for Windows Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0037,
            "epssPercentile": 0.30138,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59137",
            "title": "Windows Event Logging Service Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31953,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59138",
            "title": "Microsoft Remote Registry Service Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01042,
            "epssPercentile": 0.61833,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61345",
            "title": "Microsoft Remote Registry Service Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01042,
            "epssPercentile": 0.61834,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61347",
            "title": "Windows Event Logging Service Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61348",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0159,
            "epssPercentile": 0.7403,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61349",
            "title": "Windows Work Folder Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00238,
            "epssPercentile": 0.14813,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61350",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00449,
            "epssPercentile": 0.3762,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61352",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00428,
            "epssPercentile": 0.35876,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61353",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61360",
            "title": "Windows GDI Information Disclosure Vulnerability",
            "summary": "Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31956,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61363",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00625,
            "epssPercentile": 0.47727,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61364",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61365",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61366",
            "title": "Windows Network Connection Broker Elevation of Privilege Vulnerability",
            "summary": "Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61367",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61368",
            "title": "Windows Hyper-V Information Disclosure Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally.",
            "score": 5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00372,
            "epssPercentile": 0.30393,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61918",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00869,
            "epssPercentile": 0.56428,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61920",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a network.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00484,
            "epssPercentile": 0.39993,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61921",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00829,
            "epssPercentile": 0.55174,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61924",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00829,
            "epssPercentile": 0.55173,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61925",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00381,
            "epssPercentile": 0.31232,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61926",
            "title": "Windows USB Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61928",
            "title": "Windows Hello Tampering Vulnerability",
            "summary": "Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0021,
            "epssPercentile": 0.11257,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61930",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02092,
            "epssPercentile": 0.80405,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61932",
            "title": "Windows DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.2356,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61937",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61939",
            "title": "Winlogon Elevation of Privilege Vulnerability",
            "summary": "Use after free in Winlogon allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15759,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62692",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62696",
            "title": "Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03401,
            "epssPercentile": 0.88059,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62698",
            "title": "Microsoft Digest Authentication Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00361,
            "epssPercentile": 0.29142,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62699",
            "title": "Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to execute code with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00409,
            "epssPercentile": 0.34136,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62700",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62701",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62707",
            "title": "Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62709",
            "title": "Windows GDI+ Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31908,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62710",
            "title": "Windows Device Association Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62711",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23518,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62712",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0038,
            "epssPercentile": 0.31158,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62714",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00468,
            "epssPercentile": 0.3888,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62715",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0048,
            "epssPercentile": 0.3977,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62716",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00468,
            "epssPercentile": 0.3888,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62717",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62718",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0048,
            "epssPercentile": 0.39771,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62719",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62720",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00468,
            "epssPercentile": 0.3888,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62721",
            "title": "Windows User-Mode Power Service (UMPS) Elevation of Privilege Vulnerability",
            "summary": "Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0038,
            "epssPercentile": 0.31198,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62723",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62724",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15758,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62725",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09788,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62726",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15758,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62727",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00186,
            "epssPercentile": 0.08256,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62728",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62729",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62730",
            "title": "Windows Wired AutoConfig Service Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62732",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62733",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62734",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62735",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00476,
            "epssPercentile": 0.39473,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62738",
            "title": "Windows Management Instrumentation Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62740",
            "title": "Windows Imaging Component Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31908,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62741",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02092,
            "epssPercentile": 0.80405,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62742",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0048,
            "epssPercentile": 0.39771,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62743",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31954,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62745",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00361,
            "epssPercentile": 0.29156,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62746",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31954,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62747",
            "title": "Windows Device Association Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23557,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62748",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08564,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62750",
            "title": "Windows HTTP Protocol Stack Tampering Vulnerability",
            "summary": "Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00574,
            "epssPercentile": 0.45288,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62752",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23556,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62753",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00207,
            "epssPercentile": 0.10799,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62754",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62755",
            "title": "Windows DHCP Client Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62757",
            "title": "Windows Schannel Security Feature Bypass Vulnerability",
            "summary": "Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00255,
            "epssPercentile": 0.16929,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62758",
            "title": "Windows Remote Access Connection Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.14966,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62761",
            "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00355,
            "epssPercentile": 0.28559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62768",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62769",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62770",
            "title": "Windows Shell Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15007,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62773",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09787,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62774",
            "title": "Windows Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09787,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62776",
            "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00271,
            "epssPercentile": 0.19237,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62777",
            "title": "Windows License Manager Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11773,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62778",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00506,
            "epssPercentile": 0.41401,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62781",
            "title": "RPC Runtime Library Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00519,
            "epssPercentile": 0.42242,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62782",
            "title": "Windows SMB Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00868,
            "epssPercentile": 0.56396,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62784",
            "title": "Microsoft Local Security Authority Server (lsasrv) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00934,
            "epssPercentile": 0.58442,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62785",
            "title": "Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00837,
            "epssPercentile": 0.55424,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62786",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62787",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows DNS allows an authorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0053,
            "epssPercentile": 0.4292,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62790",
            "title": "Windows SMBv3 Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00664,
            "epssPercentile": 0.49429,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62792",
            "title": "Windows TCP/IP Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00708,
            "epssPercentile": 0.51162,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62793",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23712,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62795",
            "title": "Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00607,
            "epssPercentile": 0.46873,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62796",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62797",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00334,
            "epssPercentile": 0.26156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62800",
            "title": "Windows SMBv3 Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00934,
            "epssPercentile": 0.58442,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62803",
            "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00371,
            "epssPercentile": 0.30191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62807",
            "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00371,
            "epssPercentile": 0.30191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62812",
            "title": "Windows DHCP Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00291,
            "epssPercentile": 0.21362,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62814",
            "title": "Windows DHCP Server Information Disclosure Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00537,
            "epssPercentile": 0.43342,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62816",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00393,
            "epssPercentile": 0.32547,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62818",
            "title": "Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability",
            "summary": "Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00972,
            "epssPercentile": 0.59701,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62819",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00579,
            "epssPercentile": 0.45525,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62820",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00543,
            "epssPercentile": 0.43643,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62822",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00633,
            "epssPercentile": 0.48082,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62823",
            "title": "Windows DHCP Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00662,
            "epssPercentile": 0.49371,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62824",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00625,
            "epssPercentile": 0.47758,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62876",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62877",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62878",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0126,
            "epssPercentile": 0.67668,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62880",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15004,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62881",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62883",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17628,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62885",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62887",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22166,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62889",
            "title": "Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability",
            "summary": "Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0056,
            "epssPercentile": 0.44552,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62890",
            "title": "Windows GDI+ Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00269,
            "epssPercentile": 0.18868,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62893",
            "title": "Windows Deployment Services TFTP Server Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02732,
            "epssPercentile": 0.85128,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62894",
            "title": "Windows DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00249,
            "epssPercentile": 0.16159,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62908",
            "title": "Windows Backup Engine Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00153,
            "epssPercentile": 0.04738,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65662",
            "title": "Windows GDI Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65671",
            "title": "Remote Access API Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00257,
            "epssPercentile": 0.17266,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65678",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11662,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65679",
            "title": "Windows iSCSI Target Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00566,
            "epssPercentile": 0.44906,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65681",
            "title": "Windows iSCSI Target Service Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00886,
            "epssPercentile": 0.56926,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65774",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00257,
            "epssPercentile": 0.17266,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65775",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02609,
            "epssPercentile": 0.84381,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65784",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00299,
            "epssPercentile": 0.22201,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65786",
            "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65787",
            "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.2356,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65789",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00544,
            "epssPercentile": 0.43722,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65790",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15007,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65791",
            "title": "Windows iSCSI Target Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.006,
            "epssPercentile": 0.46555,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65794",
            "title": "Windows SMB Client Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00651,
            "epssPercentile": 0.48924,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65795",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17627,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65796",
            "title": "Windows iSCSI Target Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00528,
            "epssPercentile": 0.42787,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65797",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17582,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65798",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17628,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65799",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00253,
            "epssPercentile": 0.16631,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65814",
            "title": "Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00252,
            "epssPercentile": 0.16578,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66799",
            "title": "Windows Key Guard Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00269,
            "epssPercentile": 0.18868,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-6726",
            "title": "An information leakage vulnerability in the TCG TPM 2.0 reference code.",
            "summary": "An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key. See also TCG VRT0010.",
            "score": 7.9,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00215,
            "epssPercentile": 0.11783,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-6727",
            "title": "CVE-2026-6727",
            "summary": "A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with access to the TPM command interface may be able to exploit timing differences to recover information that could allow decryption of ciphertexts encrypted to TPM-managed RSA keys, including the RSA Endorsement Key (EK), including import blobs, credential blobs, and session salts. Under certain conditi",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00203,
            "epssPercentile": 0.10248,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68819",
            "title": "Windows Network File System Denial of Service Vulnerability",
            "summary": "Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00684,
            "epssPercentile": 0.50268,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68820",
            "title": "Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability",
            "summary": "Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2026-08-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.06184,
            "epssPercentile": 0.93023,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2026-08-25 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70304",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00316,
            "epssPercentile": 0.24068,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70307",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00322,
            "epssPercentile": 0.24811,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70330",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00316,
            "epssPercentile": 0.24068,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70344",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70345",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70346",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70347",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23517,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Exploitation reported by the vendor source",
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-65791",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-windows-kb5120994",
      "slug": "microsoft-2026-08-windows-kb5120994",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5120994",
      "title": "Deploy Microsoft Windows security update KB5120994",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5120994",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows 11 Version 25H2 for ARM64-based Systems, plus 1 more",
      "platform": "Windows",
      "release_version": "10.0.26100.9106, 10.0.26200.9106",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 196 linked CVEs for Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows 11 Version 25H2 for ARM64-based Systems, plus 1 more. Microsoft reports exploitation for CVE-2026-68820.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 196,
        "ids": [
          "CVE-2026-42976",
          "CVE-2026-49179",
          "CVE-2026-50472",
          "CVE-2026-54113",
          "CVE-2026-54984",
          "CVE-2026-56179",
          "CVE-2026-59122",
          "CVE-2026-59125",
          "CVE-2026-59126",
          "CVE-2026-59127",
          "CVE-2026-59128",
          "CVE-2026-59130",
          "CVE-2026-59131",
          "CVE-2026-59132",
          "CVE-2026-59134",
          "CVE-2026-59135",
          "CVE-2026-59136",
          "CVE-2026-59137",
          "CVE-2026-59138",
          "CVE-2026-61345",
          "CVE-2026-61346",
          "CVE-2026-61347",
          "CVE-2026-61348",
          "CVE-2026-61349",
          "CVE-2026-61350",
          "CVE-2026-61352",
          "CVE-2026-61353",
          "CVE-2026-61355",
          "CVE-2026-61356",
          "CVE-2026-61357",
          "CVE-2026-61358",
          "CVE-2026-61359",
          "CVE-2026-61360",
          "CVE-2026-61361",
          "CVE-2026-61363",
          "CVE-2026-61364",
          "CVE-2026-61365",
          "CVE-2026-61366",
          "CVE-2026-61367",
          "CVE-2026-61368",
          "CVE-2026-61918",
          "CVE-2026-61921",
          "CVE-2026-61923",
          "CVE-2026-61924",
          "CVE-2026-61925",
          "CVE-2026-61926",
          "CVE-2026-61927",
          "CVE-2026-61928",
          "CVE-2026-61929",
          "CVE-2026-61930",
          "CVE-2026-61933",
          "CVE-2026-61934",
          "CVE-2026-61936",
          "CVE-2026-61937",
          "CVE-2026-61938",
          "CVE-2026-61939",
          "CVE-2026-62688",
          "CVE-2026-62690",
          "CVE-2026-62692",
          "CVE-2026-62693",
          "CVE-2026-62695",
          "CVE-2026-62696",
          "CVE-2026-62698",
          "CVE-2026-62699",
          "CVE-2026-62700",
          "CVE-2026-62701",
          "CVE-2026-62702",
          "CVE-2026-62703",
          "CVE-2026-62705",
          "CVE-2026-62707",
          "CVE-2026-62708",
          "CVE-2026-62709",
          "CVE-2026-62710",
          "CVE-2026-62711",
          "CVE-2026-62712",
          "CVE-2026-62713",
          "CVE-2026-62717",
          "CVE-2026-62719",
          "CVE-2026-62721",
          "CVE-2026-62722",
          "CVE-2026-62723",
          "CVE-2026-62724",
          "CVE-2026-62725",
          "CVE-2026-62726",
          "CVE-2026-62727",
          "CVE-2026-62728",
          "CVE-2026-62729",
          "CVE-2026-62730",
          "CVE-2026-62732",
          "CVE-2026-62733",
          "CVE-2026-62734",
          "CVE-2026-62735",
          "CVE-2026-62736",
          "CVE-2026-62737",
          "CVE-2026-62738",
          "CVE-2026-62739",
          "CVE-2026-62740",
          "CVE-2026-62741",
          "CVE-2026-62743",
          "CVE-2026-62746",
          "CVE-2026-62747",
          "CVE-2026-62748",
          "CVE-2026-62749",
          "CVE-2026-62750",
          "CVE-2026-62751",
          "CVE-2026-62752",
          "CVE-2026-62753",
          "CVE-2026-62754",
          "CVE-2026-62755",
          "CVE-2026-62757",
          "CVE-2026-62758",
          "CVE-2026-62766",
          "CVE-2026-62768",
          "CVE-2026-62769",
          "CVE-2026-62770",
          "CVE-2026-62771",
          "CVE-2026-62773",
          "CVE-2026-62774",
          "CVE-2026-62777",
          "CVE-2026-62779",
          "CVE-2026-62780",
          "CVE-2026-62781",
          "CVE-2026-62782",
          "CVE-2026-62783",
          "CVE-2026-62784",
          "CVE-2026-62785",
          "CVE-2026-62786",
          "CVE-2026-62788",
          "CVE-2026-62790",
          "CVE-2026-62792",
          "CVE-2026-62793",
          "CVE-2026-62795",
          "CVE-2026-62796",
          "CVE-2026-62797",
          "CVE-2026-62798",
          "CVE-2026-62800",
          "CVE-2026-62811",
          "CVE-2026-62815",
          "CVE-2026-62816",
          "CVE-2026-62817",
          "CVE-2026-62819",
          "CVE-2026-62822",
          "CVE-2026-62832",
          "CVE-2026-62876",
          "CVE-2026-62877",
          "CVE-2026-62880",
          "CVE-2026-62881",
          "CVE-2026-62883",
          "CVE-2026-62885",
          "CVE-2026-62887",
          "CVE-2026-62888",
          "CVE-2026-62889",
          "CVE-2026-62890",
          "CVE-2026-62892",
          "CVE-2026-62894",
          "CVE-2026-62908",
          "CVE-2026-65662",
          "CVE-2026-65671",
          "CVE-2026-65672",
          "CVE-2026-65678",
          "CVE-2026-65773",
          "CVE-2026-65774",
          "CVE-2026-65775",
          "CVE-2026-65776",
          "CVE-2026-65777",
          "CVE-2026-65778",
          "CVE-2026-65779",
          "CVE-2026-65780",
          "CVE-2026-65781",
          "CVE-2026-65782",
          "CVE-2026-65783",
          "CVE-2026-65784",
          "CVE-2026-65785",
          "CVE-2026-65786",
          "CVE-2026-65787",
          "CVE-2026-65788",
          "CVE-2026-65790",
          "CVE-2026-65794",
          "CVE-2026-65795",
          "CVE-2026-65797",
          "CVE-2026-65798",
          "CVE-2026-65799",
          "CVE-2026-65814",
          "CVE-2026-66799",
          "CVE-2026-66804",
          "CVE-2026-6726",
          "CVE-2026-6727",
          "CVE-2026-68820",
          "CVE-2026-70304",
          "CVE-2026-70307",
          "CVE-2026-70330",
          "CVE-2026-70344",
          "CVE-2026-70345",
          "CVE-2026-70346",
          "CVE-2026-70347",
          "CVE-2026-70348"
        ],
        "details": [
          {
            "id": "CVE-2026-42976",
            "title": "Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11772,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49179",
            "title": "Windows Active Directory Domain Services Remote Code Execution Vulnerability",
            "summary": "Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00831,
            "epssPercentile": 0.55217,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50472",
            "title": "Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54113",
            "title": "Remote Procedure Call Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01126,
            "epssPercentile": 0.64162,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54984",
            "title": "Windows Imaging Component Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.006,
            "epssPercentile": 0.46535,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56179",
            "title": "Windows Network Address Translation (NAT) Spoofing Vulnerability",
            "summary": "Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.",
            "score": 8.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00234,
            "epssPercentile": 0.14223,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59122",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59125",
            "title": "Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability",
            "summary": "Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59126",
            "title": "Windows Event Logging Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59127",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23557,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59128",
            "title": "Windows Encrypting File System (EFS) Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31953,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59130",
            "title": "AMD Zen Information Disclosure Vulnerability",
            "summary": "No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00337,
            "epssPercentile": 0.26512,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59131",
            "title": "AMD Zen Information Disclosure Vulnerability",
            "summary": "No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00284,
            "epssPercentile": 0.20673,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59132",
            "title": "Windows TCP/IP Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01686,
            "epssPercentile": 0.75496,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59134",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00624,
            "epssPercentile": 0.47693,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59135",
            "title": "Microsoft Windows Search Component Information Disclosure Vulnerability",
            "summary": "Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0032,
            "epssPercentile": 0.24552,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59136",
            "title": "Microsoft COM for Windows Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0037,
            "epssPercentile": 0.30138,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59137",
            "title": "Windows Event Logging Service Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31953,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59138",
            "title": "Microsoft Remote Registry Service Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01042,
            "epssPercentile": 0.61833,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61345",
            "title": "Microsoft Remote Registry Service Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01042,
            "epssPercentile": 0.61834,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61346",
            "title": "Windows Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61347",
            "title": "Windows Event Logging Service Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61348",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0159,
            "epssPercentile": 0.7403,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61349",
            "title": "Windows Work Folder Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00238,
            "epssPercentile": 0.14813,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61350",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00449,
            "epssPercentile": 0.3762,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61352",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00428,
            "epssPercentile": 0.35876,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61353",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61355",
            "title": "Windows Sensor Data Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23556,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61356",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61357",
            "title": "Application Information Services Elevation of Privilege Vulnerability",
            "summary": "Use after free in Application Information Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23556,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61358",
            "title": "Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0368,
            "epssPercentile": 0.88942,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61359",
            "title": "Windows Storage Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00334,
            "epssPercentile": 0.26154,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61360",
            "title": "Windows GDI Information Disclosure Vulnerability",
            "summary": "Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31956,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61361",
            "title": "Windows DHCP Client Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows DHCP Client allows an authorized attacker to execute code locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61363",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00625,
            "epssPercentile": 0.47727,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61364",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61365",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61366",
            "title": "Windows Network Connection Broker Elevation of Privilege Vulnerability",
            "summary": "Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61367",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61368",
            "title": "Windows Hyper-V Information Disclosure Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally.",
            "score": 5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00372,
            "epssPercentile": 0.30393,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61918",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00869,
            "epssPercentile": 0.56428,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61921",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00829,
            "epssPercentile": 0.55174,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61923",
            "title": "Windows Display Enhancement Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61924",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00829,
            "epssPercentile": 0.55173,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61925",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00381,
            "epssPercentile": 0.31232,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61926",
            "title": "Windows USB Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61927",
            "title": "Windows Bind Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08564,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61928",
            "title": "Windows Hello Tampering Vulnerability",
            "summary": "Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0021,
            "epssPercentile": 0.11257,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61929",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01676,
            "epssPercentile": 0.75331,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61930",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02092,
            "epssPercentile": 0.80405,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61933",
            "title": "Windows DWM Core Library Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61934",
            "title": "Windows Bind Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61936",
            "title": "Windows Defender Firewall Service Security Feature Bypass Vulnerability",
            "summary": "Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00282,
            "epssPercentile": 0.20397,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61937",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61938",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61939",
            "title": "Winlogon Elevation of Privilege Vulnerability",
            "summary": "Use after free in Winlogon allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15759,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62688",
            "title": "Windows MIDI Service Module Elevation of Privileges Vulnerability",
            "summary": "Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00361,
            "epssPercentile": 0.29142,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62690",
            "title": "Windows Push Notifications Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62692",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62693",
            "title": "Windows MIDI Service Module Elevation of Privileges Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62695",
            "title": "Windows Storage Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.2356,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62696",
            "title": "Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03401,
            "epssPercentile": 0.88059,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62698",
            "title": "Microsoft Digest Authentication Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00361,
            "epssPercentile": 0.29142,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62699",
            "title": "Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to execute code with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00409,
            "epssPercentile": 0.34136,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62700",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62701",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62702",
            "title": "Windows Graphics Kernel Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00943,
            "epssPercentile": 0.58737,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62703",
            "title": "Windows DWM Core Library Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31954,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62705",
            "title": "Microsoft Brokering File System Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62707",
            "title": "Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62708",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00316,
            "epssPercentile": 0.24162,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62709",
            "title": "Windows GDI+ Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31908,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62710",
            "title": "Windows Device Association Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62711",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23518,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62712",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0038,
            "epssPercentile": 0.31158,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62713",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0195,
            "epssPercentile": 0.78893,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62717",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62719",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62721",
            "title": "Windows User-Mode Power Service (UMPS) Elevation of Privilege Vulnerability",
            "summary": "Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0038,
            "epssPercentile": 0.31198,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62722",
            "title": "Microsoft Brokering File System Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Brokering File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62723",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62724",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15758,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62725",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09788,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62726",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15758,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62727",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00186,
            "epssPercentile": 0.08256,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62728",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62729",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62730",
            "title": "Windows Wired AutoConfig Service Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62732",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62733",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62734",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62735",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00476,
            "epssPercentile": 0.39473,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62736",
            "title": "Windows DHCP Client Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15004,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62737",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02844,
            "epssPercentile": 0.85765,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62738",
            "title": "Windows Management Instrumentation Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62739",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00249,
            "epssPercentile": 0.1616,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62740",
            "title": "Windows Imaging Component Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31908,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62741",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02092,
            "epssPercentile": 0.80405,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62743",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31954,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62746",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31954,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62747",
            "title": "Windows Device Association Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23557,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62748",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08564,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62749",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09786,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62750",
            "title": "Windows HTTP Protocol Stack Tampering Vulnerability",
            "summary": "Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00574,
            "epssPercentile": 0.45288,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62751",
            "title": "Windows Projected File System Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23557,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62752",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23556,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62753",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00207,
            "epssPercentile": 0.10799,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62754",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62755",
            "title": "Windows DHCP Client Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62757",
            "title": "Windows Schannel Security Feature Bypass Vulnerability",
            "summary": "Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00255,
            "epssPercentile": 0.16929,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62758",
            "title": "Windows Remote Access Connection Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.14966,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62766",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Double free in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01522,
            "epssPercentile": 0.72941,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62768",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62769",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62770",
            "title": "Windows Shell Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15007,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62771",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00249,
            "epssPercentile": 0.1616,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62773",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09787,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62774",
            "title": "Windows Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09787,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62777",
            "title": "Windows License Manager Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11773,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62779",
            "title": "Windows Schannel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Schannel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62780",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10199,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62781",
            "title": "RPC Runtime Library Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00519,
            "epssPercentile": 0.42242,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62782",
            "title": "Windows SMB Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00868,
            "epssPercentile": 0.56396,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62783",
            "title": "Windows Remote Access Connection Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01951,
            "epssPercentile": 0.78901,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62784",
            "title": "Microsoft Local Security Authority Server (lsasrv) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00934,
            "epssPercentile": 0.58442,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62785",
            "title": "Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00837,
            "epssPercentile": 0.55424,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62786",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62788",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26033,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62790",
            "title": "Windows SMBv3 Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00664,
            "epssPercentile": 0.49429,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62792",
            "title": "Windows TCP/IP Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00708,
            "epssPercentile": 0.51162,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62793",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23712,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62795",
            "title": "Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00607,
            "epssPercentile": 0.46873,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62796",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62797",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00334,
            "epssPercentile": 0.26156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62798",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23712,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62800",
            "title": "Windows SMBv3 Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00934,
            "epssPercentile": 0.58442,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62811",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00334,
            "epssPercentile": 0.26156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62815",
            "title": "Microsoft QUIC Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00982,
            "epssPercentile": 0.6,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62816",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00393,
            "epssPercentile": 0.32547,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62817",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00668,
            "epssPercentile": 0.49598,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62819",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00579,
            "epssPercentile": 0.45525,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62822",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00633,
            "epssPercentile": 0.48082,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62832",
            "title": "Windows User Profile Service Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03295,
            "epssPercentile": 0.87687,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62876",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62877",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62880",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15004,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62881",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62883",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17628,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62885",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62887",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22166,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62888",
            "title": "Windows DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01951,
            "epssPercentile": 0.78901,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62889",
            "title": "Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability",
            "summary": "Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0056,
            "epssPercentile": 0.44552,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62890",
            "title": "Windows GDI+ Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00269,
            "epssPercentile": 0.18868,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62892",
            "title": "Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability",
            "summary": "Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09787,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62894",
            "title": "Windows DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00249,
            "epssPercentile": 0.16159,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62908",
            "title": "Windows Backup Engine Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00153,
            "epssPercentile": 0.04738,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65662",
            "title": "Windows GDI Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65671",
            "title": "Remote Access API Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00257,
            "epssPercentile": 0.17266,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65672",
            "title": "Remote Access API Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00257,
            "epssPercentile": 0.17267,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65678",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11662,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65773",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00242,
            "epssPercentile": 0.15314,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65774",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00257,
            "epssPercentile": 0.17266,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65775",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02609,
            "epssPercentile": 0.84381,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65776",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00225,
            "epssPercentile": 0.13105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65777",
            "title": "Active Directory Security Feature Bypass Vulnerability",
            "summary": "Inadequate encryption strength in Windows Active Directory allows an authorized attacker to bypass a security feature over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00288,
            "epssPercentile": 0.21003,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65778",
            "title": "Windows Autopilot Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11661,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65779",
            "title": "Windows Autopilot Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11662,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65780",
            "title": "Windows Autopilot Elevation of Privilege Vulnerability",
            "summary": "Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09786,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65781",
            "title": "Windows Autopilot Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09786,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65782",
            "title": "Windows Autopilot Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09786,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65783",
            "title": "Windows Autopilot Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09787,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65784",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00299,
            "epssPercentile": 0.22201,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65785",
            "title": "Windows DHCP Client Denial of Service Vulnerability",
            "summary": "Uncontrolled resource consumption in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00378,
            "epssPercentile": 0.30924,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65786",
            "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65787",
            "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.2356,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65788",
            "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
            "summary": "Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01676,
            "epssPercentile": 0.75331,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65790",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15007,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65794",
            "title": "Windows SMB Client Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00651,
            "epssPercentile": 0.48924,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65795",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17627,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65797",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17582,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65798",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17628,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65799",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00253,
            "epssPercentile": 0.16631,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65814",
            "title": "Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00252,
            "epssPercentile": 0.16578,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66799",
            "title": "Windows Key Guard Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00269,
            "epssPercentile": 0.18868,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66804",
            "title": "Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.05309,
            "epssPercentile": 0.92057,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-6726",
            "title": "An information leakage vulnerability in the TCG TPM 2.0 reference code.",
            "summary": "An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key. See also TCG VRT0010.",
            "score": 7.9,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00215,
            "epssPercentile": 0.11783,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-6727",
            "title": "CVE-2026-6727",
            "summary": "A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with access to the TPM command interface may be able to exploit timing differences to recover information that could allow decryption of ciphertexts encrypted to TPM-managed RSA keys, including the RSA Endorsement Key (EK), including import blobs, credential blobs, and session salts. Under certain conditi",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00203,
            "epssPercentile": 0.10248,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68820",
            "title": "Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability",
            "summary": "Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2026-08-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.06184,
            "epssPercentile": 0.93023,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2026-08-25 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70304",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00316,
            "epssPercentile": 0.24068,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70307",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00322,
            "epssPercentile": 0.24811,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70330",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00316,
            "epssPercentile": 0.24068,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70344",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70345",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70346",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70347",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23517,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70348",
            "title": "Windows Management Services Denial of Service Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00425,
            "epssPercentile": 0.35642,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Exploitation reported by the vendor source",
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-62815",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-windows-kb5121000",
      "slug": "microsoft-2026-08-windows-kb5121000",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5121000",
      "title": "Deploy Microsoft Windows security update KB5121000",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5121000",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Windows 11 Version 26H1 for ARM64-based Systems, Windows 11 version 26H1 for x64-based Systems",
      "platform": "Windows",
      "release_version": "10.0.28000.2704",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 198 linked CVEs for Windows 11 Version 26H1 for ARM64-based Systems, Windows 11 version 26H1 for x64-based Systems. Microsoft reports exploitation for CVE-2026-68820.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 198,
        "ids": [
          "CVE-2026-42976",
          "CVE-2026-49179",
          "CVE-2026-50472",
          "CVE-2026-54113",
          "CVE-2026-54984",
          "CVE-2026-56179",
          "CVE-2026-59122",
          "CVE-2026-59125",
          "CVE-2026-59126",
          "CVE-2026-59127",
          "CVE-2026-59128",
          "CVE-2026-59130",
          "CVE-2026-59131",
          "CVE-2026-59132",
          "CVE-2026-59134",
          "CVE-2026-59135",
          "CVE-2026-59136",
          "CVE-2026-59137",
          "CVE-2026-59138",
          "CVE-2026-61345",
          "CVE-2026-61346",
          "CVE-2026-61347",
          "CVE-2026-61348",
          "CVE-2026-61349",
          "CVE-2026-61350",
          "CVE-2026-61352",
          "CVE-2026-61353",
          "CVE-2026-61355",
          "CVE-2026-61356",
          "CVE-2026-61357",
          "CVE-2026-61358",
          "CVE-2026-61359",
          "CVE-2026-61360",
          "CVE-2026-61361",
          "CVE-2026-61363",
          "CVE-2026-61364",
          "CVE-2026-61365",
          "CVE-2026-61366",
          "CVE-2026-61367",
          "CVE-2026-61368",
          "CVE-2026-61918",
          "CVE-2026-61920",
          "CVE-2026-61921",
          "CVE-2026-61923",
          "CVE-2026-61924",
          "CVE-2026-61925",
          "CVE-2026-61926",
          "CVE-2026-61927",
          "CVE-2026-61928",
          "CVE-2026-61929",
          "CVE-2026-61930",
          "CVE-2026-61933",
          "CVE-2026-61934",
          "CVE-2026-61936",
          "CVE-2026-61937",
          "CVE-2026-61938",
          "CVE-2026-61939",
          "CVE-2026-62688",
          "CVE-2026-62690",
          "CVE-2026-62692",
          "CVE-2026-62693",
          "CVE-2026-62695",
          "CVE-2026-62696",
          "CVE-2026-62698",
          "CVE-2026-62699",
          "CVE-2026-62700",
          "CVE-2026-62701",
          "CVE-2026-62702",
          "CVE-2026-62703",
          "CVE-2026-62705",
          "CVE-2026-62707",
          "CVE-2026-62708",
          "CVE-2026-62709",
          "CVE-2026-62710",
          "CVE-2026-62711",
          "CVE-2026-62712",
          "CVE-2026-62713",
          "CVE-2026-62717",
          "CVE-2026-62719",
          "CVE-2026-62721",
          "CVE-2026-62722",
          "CVE-2026-62723",
          "CVE-2026-62724",
          "CVE-2026-62725",
          "CVE-2026-62726",
          "CVE-2026-62727",
          "CVE-2026-62728",
          "CVE-2026-62729",
          "CVE-2026-62730",
          "CVE-2026-62732",
          "CVE-2026-62733",
          "CVE-2026-62734",
          "CVE-2026-62735",
          "CVE-2026-62736",
          "CVE-2026-62737",
          "CVE-2026-62738",
          "CVE-2026-62739",
          "CVE-2026-62740",
          "CVE-2026-62741",
          "CVE-2026-62743",
          "CVE-2026-62746",
          "CVE-2026-62747",
          "CVE-2026-62748",
          "CVE-2026-62749",
          "CVE-2026-62750",
          "CVE-2026-62751",
          "CVE-2026-62752",
          "CVE-2026-62753",
          "CVE-2026-62754",
          "CVE-2026-62755",
          "CVE-2026-62757",
          "CVE-2026-62758",
          "CVE-2026-62766",
          "CVE-2026-62768",
          "CVE-2026-62769",
          "CVE-2026-62770",
          "CVE-2026-62771",
          "CVE-2026-62772",
          "CVE-2026-62773",
          "CVE-2026-62774",
          "CVE-2026-62775",
          "CVE-2026-62777",
          "CVE-2026-62779",
          "CVE-2026-62780",
          "CVE-2026-62781",
          "CVE-2026-62782",
          "CVE-2026-62783",
          "CVE-2026-62784",
          "CVE-2026-62785",
          "CVE-2026-62786",
          "CVE-2026-62788",
          "CVE-2026-62790",
          "CVE-2026-62792",
          "CVE-2026-62793",
          "CVE-2026-62795",
          "CVE-2026-62796",
          "CVE-2026-62797",
          "CVE-2026-62798",
          "CVE-2026-62799",
          "CVE-2026-62800",
          "CVE-2026-62811",
          "CVE-2026-62815",
          "CVE-2026-62816",
          "CVE-2026-62817",
          "CVE-2026-62819",
          "CVE-2026-62822",
          "CVE-2026-62832",
          "CVE-2026-62876",
          "CVE-2026-62877",
          "CVE-2026-62880",
          "CVE-2026-62881",
          "CVE-2026-62883",
          "CVE-2026-62885",
          "CVE-2026-62887",
          "CVE-2026-62888",
          "CVE-2026-62889",
          "CVE-2026-62890",
          "CVE-2026-62892",
          "CVE-2026-62894",
          "CVE-2026-62908",
          "CVE-2026-65662",
          "CVE-2026-65671",
          "CVE-2026-65672",
          "CVE-2026-65678",
          "CVE-2026-65773",
          "CVE-2026-65774",
          "CVE-2026-65775",
          "CVE-2026-65776",
          "CVE-2026-65777",
          "CVE-2026-65779",
          "CVE-2026-65780",
          "CVE-2026-65784",
          "CVE-2026-65785",
          "CVE-2026-65786",
          "CVE-2026-65787",
          "CVE-2026-65788",
          "CVE-2026-65790",
          "CVE-2026-65794",
          "CVE-2026-65795",
          "CVE-2026-65797",
          "CVE-2026-65798",
          "CVE-2026-65799",
          "CVE-2026-65814",
          "CVE-2026-66799",
          "CVE-2026-66802",
          "CVE-2026-66804",
          "CVE-2026-6726",
          "CVE-2026-6727",
          "CVE-2026-68820",
          "CVE-2026-70304",
          "CVE-2026-70307",
          "CVE-2026-70330",
          "CVE-2026-70344",
          "CVE-2026-70345",
          "CVE-2026-70346",
          "CVE-2026-70347",
          "CVE-2026-70348",
          "CVE-2026-72971"
        ],
        "details": [
          {
            "id": "CVE-2026-42976",
            "title": "Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11772,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49179",
            "title": "Windows Active Directory Domain Services Remote Code Execution Vulnerability",
            "summary": "Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00831,
            "epssPercentile": 0.55217,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50472",
            "title": "Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54113",
            "title": "Remote Procedure Call Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01126,
            "epssPercentile": 0.64162,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54984",
            "title": "Windows Imaging Component Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.006,
            "epssPercentile": 0.46535,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56179",
            "title": "Windows Network Address Translation (NAT) Spoofing Vulnerability",
            "summary": "Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.",
            "score": 8.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00234,
            "epssPercentile": 0.14223,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59122",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59125",
            "title": "Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability",
            "summary": "Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59126",
            "title": "Windows Event Logging Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59127",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23557,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59128",
            "title": "Windows Encrypting File System (EFS) Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31953,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59130",
            "title": "AMD Zen Information Disclosure Vulnerability",
            "summary": "No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00337,
            "epssPercentile": 0.26512,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59131",
            "title": "AMD Zen Information Disclosure Vulnerability",
            "summary": "No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00284,
            "epssPercentile": 0.20673,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59132",
            "title": "Windows TCP/IP Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01686,
            "epssPercentile": 0.75496,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59134",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00624,
            "epssPercentile": 0.47693,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59135",
            "title": "Microsoft Windows Search Component Information Disclosure Vulnerability",
            "summary": "Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0032,
            "epssPercentile": 0.24552,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59136",
            "title": "Microsoft COM for Windows Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0037,
            "epssPercentile": 0.30138,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59137",
            "title": "Windows Event Logging Service Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31953,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59138",
            "title": "Microsoft Remote Registry Service Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01042,
            "epssPercentile": 0.61833,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61345",
            "title": "Microsoft Remote Registry Service Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01042,
            "epssPercentile": 0.61834,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61346",
            "title": "Windows Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61347",
            "title": "Windows Event Logging Service Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61348",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0159,
            "epssPercentile": 0.7403,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61349",
            "title": "Windows Work Folder Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00238,
            "epssPercentile": 0.14813,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61350",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00449,
            "epssPercentile": 0.3762,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61352",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00428,
            "epssPercentile": 0.35876,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61353",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61355",
            "title": "Windows Sensor Data Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23556,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61356",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61357",
            "title": "Application Information Services Elevation of Privilege Vulnerability",
            "summary": "Use after free in Application Information Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23556,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61358",
            "title": "Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0368,
            "epssPercentile": 0.88942,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61359",
            "title": "Windows Storage Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00334,
            "epssPercentile": 0.26154,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61360",
            "title": "Windows GDI Information Disclosure Vulnerability",
            "summary": "Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31956,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61361",
            "title": "Windows DHCP Client Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows DHCP Client allows an authorized attacker to execute code locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61363",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00625,
            "epssPercentile": 0.47727,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61364",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61365",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61366",
            "title": "Windows Network Connection Broker Elevation of Privilege Vulnerability",
            "summary": "Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61367",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61368",
            "title": "Windows Hyper-V Information Disclosure Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally.",
            "score": 5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00372,
            "epssPercentile": 0.30393,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61918",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00869,
            "epssPercentile": 0.56428,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61920",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a network.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00484,
            "epssPercentile": 0.39993,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61921",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00829,
            "epssPercentile": 0.55174,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61923",
            "title": "Windows Display Enhancement Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61924",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00829,
            "epssPercentile": 0.55173,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61925",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00381,
            "epssPercentile": 0.31232,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61926",
            "title": "Windows USB Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61927",
            "title": "Windows Bind Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08564,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61928",
            "title": "Windows Hello Tampering Vulnerability",
            "summary": "Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0021,
            "epssPercentile": 0.11257,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61929",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01676,
            "epssPercentile": 0.75331,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61930",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02092,
            "epssPercentile": 0.80405,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61933",
            "title": "Windows DWM Core Library Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61934",
            "title": "Windows Bind Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61936",
            "title": "Windows Defender Firewall Service Security Feature Bypass Vulnerability",
            "summary": "Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00282,
            "epssPercentile": 0.20397,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61937",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61938",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61939",
            "title": "Winlogon Elevation of Privilege Vulnerability",
            "summary": "Use after free in Winlogon allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15759,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62688",
            "title": "Windows MIDI Service Module Elevation of Privileges Vulnerability",
            "summary": "Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00361,
            "epssPercentile": 0.29142,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62690",
            "title": "Windows Push Notifications Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62692",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62693",
            "title": "Windows MIDI Service Module Elevation of Privileges Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62695",
            "title": "Windows Storage Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.2356,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62696",
            "title": "Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03401,
            "epssPercentile": 0.88059,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62698",
            "title": "Microsoft Digest Authentication Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00361,
            "epssPercentile": 0.29142,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62699",
            "title": "Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to execute code with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00409,
            "epssPercentile": 0.34136,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62700",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62701",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62702",
            "title": "Windows Graphics Kernel Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00943,
            "epssPercentile": 0.58737,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62703",
            "title": "Windows DWM Core Library Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31954,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62705",
            "title": "Microsoft Brokering File System Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62707",
            "title": "Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62708",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00316,
            "epssPercentile": 0.24162,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62709",
            "title": "Windows GDI+ Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31908,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62710",
            "title": "Windows Device Association Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62711",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23518,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62712",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0038,
            "epssPercentile": 0.31158,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62713",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0195,
            "epssPercentile": 0.78893,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62717",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62719",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62721",
            "title": "Windows User-Mode Power Service (UMPS) Elevation of Privilege Vulnerability",
            "summary": "Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0038,
            "epssPercentile": 0.31198,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62722",
            "title": "Microsoft Brokering File System Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Brokering File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62723",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62724",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15758,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62725",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09788,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62726",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15758,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62727",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00186,
            "epssPercentile": 0.08256,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62728",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62729",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62730",
            "title": "Windows Wired AutoConfig Service Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62732",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62733",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62734",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62735",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00476,
            "epssPercentile": 0.39473,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62736",
            "title": "Windows DHCP Client Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15004,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62737",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02844,
            "epssPercentile": 0.85765,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62738",
            "title": "Windows Management Instrumentation Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62739",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00249,
            "epssPercentile": 0.1616,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62740",
            "title": "Windows Imaging Component Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31908,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62741",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02092,
            "epssPercentile": 0.80405,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62743",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31954,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62746",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31954,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62747",
            "title": "Windows Device Association Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23557,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62748",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08564,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62749",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09786,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62750",
            "title": "Windows HTTP Protocol Stack Tampering Vulnerability",
            "summary": "Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00574,
            "epssPercentile": 0.45288,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62751",
            "title": "Windows Projected File System Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23557,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62752",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23556,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62753",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00207,
            "epssPercentile": 0.10799,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62754",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62755",
            "title": "Windows DHCP Client Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62757",
            "title": "Windows Schannel Security Feature Bypass Vulnerability",
            "summary": "Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00255,
            "epssPercentile": 0.16929,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62758",
            "title": "Windows Remote Access Connection Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.14966,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62766",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Double free in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01522,
            "epssPercentile": 0.72941,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62768",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62769",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62770",
            "title": "Windows Shell Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15007,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62771",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00249,
            "epssPercentile": 0.1616,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62772",
            "title": "Windows Container Isolation FS Filter Driver (unionfs.sys) Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15007,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62773",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09787,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62774",
            "title": "Windows Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09787,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62775",
            "title": "Windows Container Isolation FS Filter Driver (unionfs.sys) Information Disclosure Vulnerability",
            "summary": "Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00259,
            "epssPercentile": 0.17386,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62777",
            "title": "Windows License Manager Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11773,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62779",
            "title": "Windows Schannel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Schannel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62780",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10199,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62781",
            "title": "RPC Runtime Library Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00519,
            "epssPercentile": 0.42242,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62782",
            "title": "Windows SMB Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00868,
            "epssPercentile": 0.56396,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62783",
            "title": "Windows Remote Access Connection Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01951,
            "epssPercentile": 0.78901,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62784",
            "title": "Microsoft Local Security Authority Server (lsasrv) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00934,
            "epssPercentile": 0.58442,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62785",
            "title": "Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00837,
            "epssPercentile": 0.55424,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62786",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62788",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26033,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62790",
            "title": "Windows SMBv3 Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00664,
            "epssPercentile": 0.49429,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62792",
            "title": "Windows TCP/IP Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00708,
            "epssPercentile": 0.51162,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62793",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23712,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62795",
            "title": "Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00607,
            "epssPercentile": 0.46873,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62796",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62797",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00334,
            "epssPercentile": 0.26156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62798",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23712,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62799",
            "title": "Windows SMB Client Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows SMB Client allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00257,
            "epssPercentile": 0.17267,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62800",
            "title": "Windows SMBv3 Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00934,
            "epssPercentile": 0.58442,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62811",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00334,
            "epssPercentile": 0.26156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62815",
            "title": "Microsoft QUIC Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00982,
            "epssPercentile": 0.6,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62816",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00393,
            "epssPercentile": 0.32547,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62817",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00668,
            "epssPercentile": 0.49598,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62819",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00579,
            "epssPercentile": 0.45525,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62822",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00633,
            "epssPercentile": 0.48082,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62832",
            "title": "Windows User Profile Service Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03295,
            "epssPercentile": 0.87687,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62876",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62877",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62880",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15004,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62881",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62883",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17628,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62885",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62887",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22166,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62888",
            "title": "Windows DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01951,
            "epssPercentile": 0.78901,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62889",
            "title": "Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability",
            "summary": "Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0056,
            "epssPercentile": 0.44552,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62890",
            "title": "Windows GDI+ Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00269,
            "epssPercentile": 0.18868,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62892",
            "title": "Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability",
            "summary": "Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09787,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62894",
            "title": "Windows DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00249,
            "epssPercentile": 0.16159,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62908",
            "title": "Windows Backup Engine Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00153,
            "epssPercentile": 0.04738,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65662",
            "title": "Windows GDI Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65671",
            "title": "Remote Access API Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00257,
            "epssPercentile": 0.17266,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65672",
            "title": "Remote Access API Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00257,
            "epssPercentile": 0.17267,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65678",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11662,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65773",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00242,
            "epssPercentile": 0.15314,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65774",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00257,
            "epssPercentile": 0.17266,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65775",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02609,
            "epssPercentile": 0.84381,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65776",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00225,
            "epssPercentile": 0.13105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65777",
            "title": "Active Directory Security Feature Bypass Vulnerability",
            "summary": "Inadequate encryption strength in Windows Active Directory allows an authorized attacker to bypass a security feature over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00288,
            "epssPercentile": 0.21003,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65779",
            "title": "Windows Autopilot Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11662,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65780",
            "title": "Windows Autopilot Elevation of Privilege Vulnerability",
            "summary": "Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09786,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65784",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00299,
            "epssPercentile": 0.22201,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65785",
            "title": "Windows DHCP Client Denial of Service Vulnerability",
            "summary": "Uncontrolled resource consumption in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00378,
            "epssPercentile": 0.30924,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65786",
            "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65787",
            "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.2356,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65788",
            "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
            "summary": "Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01676,
            "epssPercentile": 0.75331,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65790",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15007,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65794",
            "title": "Windows SMB Client Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00651,
            "epssPercentile": 0.48924,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65795",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17627,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65797",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17582,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65798",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17628,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65799",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00253,
            "epssPercentile": 0.16631,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65814",
            "title": "Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00252,
            "epssPercentile": 0.16578,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66799",
            "title": "Windows Key Guard Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00269,
            "epssPercentile": 0.18868,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66802",
            "title": "Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0036,
            "epssPercentile": 0.29053,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66804",
            "title": "Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.05309,
            "epssPercentile": 0.92057,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-6726",
            "title": "An information leakage vulnerability in the TCG TPM 2.0 reference code.",
            "summary": "An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key. See also TCG VRT0010.",
            "score": 7.9,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00215,
            "epssPercentile": 0.11783,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-6727",
            "title": "CVE-2026-6727",
            "summary": "A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with access to the TPM command interface may be able to exploit timing differences to recover information that could allow decryption of ciphertexts encrypted to TPM-managed RSA keys, including the RSA Endorsement Key (EK), including import blobs, credential blobs, and session salts. Under certain conditi",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00203,
            "epssPercentile": 0.10248,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68820",
            "title": "Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability",
            "summary": "Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2026-08-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.06184,
            "epssPercentile": 0.93023,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2026-08-25 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70304",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00316,
            "epssPercentile": 0.24068,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70307",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00322,
            "epssPercentile": 0.24811,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70330",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00316,
            "epssPercentile": 0.24068,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70344",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70345",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70346",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70347",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23517,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70348",
            "title": "Windows Management Services Denial of Service Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00425,
            "epssPercentile": 0.35642,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-72971",
            "title": "Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00473,
            "epssPercentile": 0.39247,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Exploitation reported by the vendor source",
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-62815",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-windows-kb5121003",
      "slug": "microsoft-2026-08-windows-kb5121003",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5121003",
      "title": "Deploy Microsoft Windows security update KB5121003",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5121003",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "revised",
      "product": "Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows 11 Version 25H2 for ARM64-based Systems, plus 1 more",
      "platform": "Windows",
      "release_version": "10.0.26100.9168, 10.0.26200.9168",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 196 linked CVEs for Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows 11 Version 25H2 for ARM64-based Systems, plus 1 more. Microsoft reports exploitation for CVE-2026-68820.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 196,
        "ids": [
          "CVE-2026-42976",
          "CVE-2026-49179",
          "CVE-2026-50472",
          "CVE-2026-54113",
          "CVE-2026-54984",
          "CVE-2026-56179",
          "CVE-2026-59122",
          "CVE-2026-59125",
          "CVE-2026-59126",
          "CVE-2026-59127",
          "CVE-2026-59128",
          "CVE-2026-59130",
          "CVE-2026-59131",
          "CVE-2026-59132",
          "CVE-2026-59134",
          "CVE-2026-59135",
          "CVE-2026-59136",
          "CVE-2026-59137",
          "CVE-2026-59138",
          "CVE-2026-61345",
          "CVE-2026-61346",
          "CVE-2026-61347",
          "CVE-2026-61348",
          "CVE-2026-61349",
          "CVE-2026-61350",
          "CVE-2026-61352",
          "CVE-2026-61353",
          "CVE-2026-61355",
          "CVE-2026-61356",
          "CVE-2026-61357",
          "CVE-2026-61358",
          "CVE-2026-61359",
          "CVE-2026-61360",
          "CVE-2026-61361",
          "CVE-2026-61363",
          "CVE-2026-61364",
          "CVE-2026-61365",
          "CVE-2026-61366",
          "CVE-2026-61367",
          "CVE-2026-61368",
          "CVE-2026-61918",
          "CVE-2026-61921",
          "CVE-2026-61923",
          "CVE-2026-61924",
          "CVE-2026-61925",
          "CVE-2026-61926",
          "CVE-2026-61927",
          "CVE-2026-61928",
          "CVE-2026-61929",
          "CVE-2026-61930",
          "CVE-2026-61933",
          "CVE-2026-61934",
          "CVE-2026-61936",
          "CVE-2026-61937",
          "CVE-2026-61938",
          "CVE-2026-61939",
          "CVE-2026-62688",
          "CVE-2026-62690",
          "CVE-2026-62692",
          "CVE-2026-62693",
          "CVE-2026-62695",
          "CVE-2026-62696",
          "CVE-2026-62698",
          "CVE-2026-62699",
          "CVE-2026-62700",
          "CVE-2026-62701",
          "CVE-2026-62702",
          "CVE-2026-62703",
          "CVE-2026-62705",
          "CVE-2026-62707",
          "CVE-2026-62708",
          "CVE-2026-62709",
          "CVE-2026-62710",
          "CVE-2026-62711",
          "CVE-2026-62712",
          "CVE-2026-62713",
          "CVE-2026-62717",
          "CVE-2026-62719",
          "CVE-2026-62721",
          "CVE-2026-62722",
          "CVE-2026-62723",
          "CVE-2026-62724",
          "CVE-2026-62725",
          "CVE-2026-62726",
          "CVE-2026-62727",
          "CVE-2026-62728",
          "CVE-2026-62729",
          "CVE-2026-62730",
          "CVE-2026-62732",
          "CVE-2026-62733",
          "CVE-2026-62734",
          "CVE-2026-62735",
          "CVE-2026-62736",
          "CVE-2026-62737",
          "CVE-2026-62738",
          "CVE-2026-62739",
          "CVE-2026-62740",
          "CVE-2026-62741",
          "CVE-2026-62743",
          "CVE-2026-62746",
          "CVE-2026-62747",
          "CVE-2026-62748",
          "CVE-2026-62749",
          "CVE-2026-62750",
          "CVE-2026-62751",
          "CVE-2026-62752",
          "CVE-2026-62753",
          "CVE-2026-62754",
          "CVE-2026-62755",
          "CVE-2026-62757",
          "CVE-2026-62758",
          "CVE-2026-62766",
          "CVE-2026-62768",
          "CVE-2026-62769",
          "CVE-2026-62770",
          "CVE-2026-62771",
          "CVE-2026-62773",
          "CVE-2026-62774",
          "CVE-2026-62777",
          "CVE-2026-62779",
          "CVE-2026-62780",
          "CVE-2026-62781",
          "CVE-2026-62782",
          "CVE-2026-62783",
          "CVE-2026-62784",
          "CVE-2026-62785",
          "CVE-2026-62786",
          "CVE-2026-62788",
          "CVE-2026-62790",
          "CVE-2026-62792",
          "CVE-2026-62793",
          "CVE-2026-62795",
          "CVE-2026-62796",
          "CVE-2026-62797",
          "CVE-2026-62798",
          "CVE-2026-62800",
          "CVE-2026-62811",
          "CVE-2026-62815",
          "CVE-2026-62816",
          "CVE-2026-62817",
          "CVE-2026-62819",
          "CVE-2026-62822",
          "CVE-2026-62832",
          "CVE-2026-62876",
          "CVE-2026-62877",
          "CVE-2026-62880",
          "CVE-2026-62881",
          "CVE-2026-62883",
          "CVE-2026-62885",
          "CVE-2026-62887",
          "CVE-2026-62888",
          "CVE-2026-62889",
          "CVE-2026-62890",
          "CVE-2026-62892",
          "CVE-2026-62894",
          "CVE-2026-62908",
          "CVE-2026-65662",
          "CVE-2026-65671",
          "CVE-2026-65672",
          "CVE-2026-65678",
          "CVE-2026-65773",
          "CVE-2026-65774",
          "CVE-2026-65775",
          "CVE-2026-65776",
          "CVE-2026-65777",
          "CVE-2026-65778",
          "CVE-2026-65779",
          "CVE-2026-65780",
          "CVE-2026-65781",
          "CVE-2026-65782",
          "CVE-2026-65783",
          "CVE-2026-65784",
          "CVE-2026-65785",
          "CVE-2026-65786",
          "CVE-2026-65787",
          "CVE-2026-65788",
          "CVE-2026-65790",
          "CVE-2026-65794",
          "CVE-2026-65795",
          "CVE-2026-65797",
          "CVE-2026-65798",
          "CVE-2026-65799",
          "CVE-2026-65814",
          "CVE-2026-66799",
          "CVE-2026-66804",
          "CVE-2026-6726",
          "CVE-2026-6727",
          "CVE-2026-68820",
          "CVE-2026-70304",
          "CVE-2026-70307",
          "CVE-2026-70330",
          "CVE-2026-70344",
          "CVE-2026-70345",
          "CVE-2026-70346",
          "CVE-2026-70347",
          "CVE-2026-70348"
        ],
        "details": [
          {
            "id": "CVE-2026-42976",
            "title": "Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11772,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-49179",
            "title": "Windows Active Directory Domain Services Remote Code Execution Vulnerability",
            "summary": "Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00831,
            "epssPercentile": 0.55217,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-50472",
            "title": "Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54113",
            "title": "Remote Procedure Call Denial of Service Vulnerability",
            "summary": "Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01126,
            "epssPercentile": 0.64162,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-54984",
            "title": "Windows Imaging Component Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.006,
            "epssPercentile": 0.46535,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-56179",
            "title": "Windows Network Address Translation (NAT) Spoofing Vulnerability",
            "summary": "Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.",
            "score": 8.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00234,
            "epssPercentile": 0.14223,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59122",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59125",
            "title": "Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability",
            "summary": "Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59126",
            "title": "Windows Event Logging Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59127",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23557,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59128",
            "title": "Windows Encrypting File System (EFS) Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31953,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59130",
            "title": "AMD Zen Information Disclosure Vulnerability",
            "summary": "No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00337,
            "epssPercentile": 0.26512,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59131",
            "title": "AMD Zen Information Disclosure Vulnerability",
            "summary": "No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00284,
            "epssPercentile": 0.20673,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59132",
            "title": "Windows TCP/IP Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01686,
            "epssPercentile": 0.75496,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59134",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00624,
            "epssPercentile": 0.47693,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59135",
            "title": "Microsoft Windows Search Component Information Disclosure Vulnerability",
            "summary": "Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0032,
            "epssPercentile": 0.24552,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59136",
            "title": "Microsoft COM for Windows Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0037,
            "epssPercentile": 0.30138,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59137",
            "title": "Windows Event Logging Service Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31953,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-59138",
            "title": "Microsoft Remote Registry Service Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01042,
            "epssPercentile": 0.61833,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61345",
            "title": "Microsoft Remote Registry Service Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01042,
            "epssPercentile": 0.61834,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61346",
            "title": "Windows Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61347",
            "title": "Windows Event Logging Service Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61348",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0159,
            "epssPercentile": 0.7403,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61349",
            "title": "Windows Work Folder Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00238,
            "epssPercentile": 0.14813,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61350",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00449,
            "epssPercentile": 0.3762,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61352",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00428,
            "epssPercentile": 0.35876,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61353",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61355",
            "title": "Windows Sensor Data Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23556,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61356",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61357",
            "title": "Application Information Services Elevation of Privilege Vulnerability",
            "summary": "Use after free in Application Information Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23556,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61358",
            "title": "Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0368,
            "epssPercentile": 0.88942,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61359",
            "title": "Windows Storage Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00334,
            "epssPercentile": 0.26154,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61360",
            "title": "Windows GDI Information Disclosure Vulnerability",
            "summary": "Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31956,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61361",
            "title": "Windows DHCP Client Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows DHCP Client allows an authorized attacker to execute code locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61363",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00625,
            "epssPercentile": 0.47727,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61364",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61365",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61366",
            "title": "Windows Network Connection Broker Elevation of Privilege Vulnerability",
            "summary": "Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61367",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.19969,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61368",
            "title": "Windows Hyper-V Information Disclosure Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally.",
            "score": 5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00372,
            "epssPercentile": 0.30393,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61918",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00869,
            "epssPercentile": 0.56428,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61921",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00829,
            "epssPercentile": 0.55174,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61923",
            "title": "Windows Display Enhancement Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61924",
            "title": "Windows Remote Desktop Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00829,
            "epssPercentile": 0.55173,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61925",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00381,
            "epssPercentile": 0.31232,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61926",
            "title": "Windows USB Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61927",
            "title": "Windows Bind Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08564,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61928",
            "title": "Windows Hello Tampering Vulnerability",
            "summary": "Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0021,
            "epssPercentile": 0.11257,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61929",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01676,
            "epssPercentile": 0.75331,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61930",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02092,
            "epssPercentile": 0.80405,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61933",
            "title": "Windows DWM Core Library Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61934",
            "title": "Windows Bind Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61936",
            "title": "Windows Defender Firewall Service Security Feature Bypass Vulnerability",
            "summary": "Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00282,
            "epssPercentile": 0.20397,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61937",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61938",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15804,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-61939",
            "title": "Winlogon Elevation of Privilege Vulnerability",
            "summary": "Use after free in Winlogon allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15759,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62688",
            "title": "Windows MIDI Service Module Elevation of Privileges Vulnerability",
            "summary": "Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00361,
            "epssPercentile": 0.29142,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62690",
            "title": "Windows Push Notifications Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62692",
            "title": "Windows Remote Desktop Services Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62693",
            "title": "Windows MIDI Service Module Elevation of Privileges Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62695",
            "title": "Windows Storage Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.2356,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62696",
            "title": "Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03401,
            "epssPercentile": 0.88059,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62698",
            "title": "Microsoft Digest Authentication Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00361,
            "epssPercentile": 0.29142,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62699",
            "title": "Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to execute code with a physical attack.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00409,
            "epssPercentile": 0.34136,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62700",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62701",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62702",
            "title": "Windows Graphics Kernel Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00943,
            "epssPercentile": 0.58737,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62703",
            "title": "Windows DWM Core Library Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31954,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62705",
            "title": "Microsoft Brokering File System Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62707",
            "title": "Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62708",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.",
            "score": 6.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00316,
            "epssPercentile": 0.24162,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62709",
            "title": "Windows GDI+ Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31908,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62710",
            "title": "Windows Device Association Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23558,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62711",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23518,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62712",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0038,
            "epssPercentile": 0.31158,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62713",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0195,
            "epssPercentile": 0.78893,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62717",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62719",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62721",
            "title": "Windows User-Mode Power Service (UMPS) Elevation of Privilege Vulnerability",
            "summary": "Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0038,
            "epssPercentile": 0.31198,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62722",
            "title": "Microsoft Brokering File System Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Brokering File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62723",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62724",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15758,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62725",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09788,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62726",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15758,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62727",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00186,
            "epssPercentile": 0.08256,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62728",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62729",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62730",
            "title": "Windows Wired AutoConfig Service Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62732",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62733",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62734",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62735",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00476,
            "epssPercentile": 0.39473,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62736",
            "title": "Windows DHCP Client Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15004,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62737",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02844,
            "epssPercentile": 0.85765,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62738",
            "title": "Windows Management Instrumentation Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31955,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62739",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00249,
            "epssPercentile": 0.1616,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62740",
            "title": "Windows Imaging Component Information Disclosure Vulnerability",
            "summary": "Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31908,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62741",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02092,
            "epssPercentile": 0.80405,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62743",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31954,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62746",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00387,
            "epssPercentile": 0.31954,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62747",
            "title": "Windows Device Association Service Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23557,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62748",
            "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00189,
            "epssPercentile": 0.08564,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62749",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09786,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62750",
            "title": "Windows HTTP Protocol Stack Tampering Vulnerability",
            "summary": "Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00574,
            "epssPercentile": 0.45288,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62751",
            "title": "Windows Projected File System Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23557,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62752",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23556,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62753",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00207,
            "epssPercentile": 0.10799,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62754",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62755",
            "title": "Windows DHCP Client Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62757",
            "title": "Windows Schannel Security Feature Bypass Vulnerability",
            "summary": "Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00255,
            "epssPercentile": 0.16929,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62758",
            "title": "Windows Remote Access Connection Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.14966,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62766",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Double free in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01522,
            "epssPercentile": 0.72941,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62768",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62769",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62770",
            "title": "Windows Shell Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15007,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62771",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00249,
            "epssPercentile": 0.1616,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62773",
            "title": "Windows Kerberos Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09787,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62774",
            "title": "Windows Graphics Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09787,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62777",
            "title": "Windows License Manager Elevation of Privilege Vulnerability",
            "summary": "Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11773,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62779",
            "title": "Windows Schannel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Schannel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62780",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00202,
            "epssPercentile": 0.10199,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62781",
            "title": "RPC Runtime Library Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00519,
            "epssPercentile": 0.42242,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62782",
            "title": "Windows SMB Client Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00868,
            "epssPercentile": 0.56396,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62783",
            "title": "Windows Remote Access Connection Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01951,
            "epssPercentile": 0.78901,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62784",
            "title": "Microsoft Local Security Authority Server (lsasrv) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00934,
            "epssPercentile": 0.58442,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62785",
            "title": "Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00837,
            "epssPercentile": 0.55424,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62786",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62788",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00333,
            "epssPercentile": 0.26033,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62790",
            "title": "Windows SMBv3 Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00664,
            "epssPercentile": 0.49429,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62792",
            "title": "Windows TCP/IP Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00708,
            "epssPercentile": 0.51162,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62793",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23712,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62795",
            "title": "Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability",
            "summary": "Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00607,
            "epssPercentile": 0.46873,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62796",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62797",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00334,
            "epssPercentile": 0.26156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62798",
            "title": "Win32k Information Disclosure Vulnerability",
            "summary": "Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23712,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62800",
            "title": "Windows SMBv3 Server Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00934,
            "epssPercentile": 0.58442,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62811",
            "title": "Windows HTTP.sys Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00334,
            "epssPercentile": 0.26156,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62815",
            "title": "Microsoft QUIC Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00982,
            "epssPercentile": 0.6,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62816",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00393,
            "epssPercentile": 0.32547,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62817",
            "title": "Windows DNS Server Remote Code Execution Vulnerability",
            "summary": "Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00668,
            "epssPercentile": 0.49598,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62819",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00579,
            "epssPercentile": 0.45525,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62822",
            "title": "Windows GDI+ Remote Code Execution Vulnerability",
            "summary": "Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00633,
            "epssPercentile": 0.48082,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62832",
            "title": "Windows User Profile Service Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03295,
            "epssPercentile": 0.87687,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62876",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15006,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62877",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62880",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15004,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62881",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62883",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17628,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62885",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62887",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00298,
            "epssPercentile": 0.22166,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62888",
            "title": "Windows DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01951,
            "epssPercentile": 0.78901,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62889",
            "title": "Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability",
            "summary": "Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0056,
            "epssPercentile": 0.44552,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62890",
            "title": "Windows GDI+ Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00269,
            "epssPercentile": 0.18868,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62892",
            "title": "Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability",
            "summary": "Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09787,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62894",
            "title": "Windows DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00249,
            "epssPercentile": 0.16159,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-62908",
            "title": "Windows Backup Engine Elevation of Privilege Vulnerability",
            "summary": "Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00153,
            "epssPercentile": 0.04738,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65662",
            "title": "Windows GDI Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00312,
            "epssPercentile": 0.23711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65671",
            "title": "Remote Access API Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00257,
            "epssPercentile": 0.17266,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65672",
            "title": "Remote Access API Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00257,
            "epssPercentile": 0.17267,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65678",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11662,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65773",
            "title": "Windows Kernel Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00242,
            "epssPercentile": 0.15314,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65774",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00257,
            "epssPercentile": 0.17266,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65775",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02609,
            "epssPercentile": 0.84381,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65776",
            "title": "Windows Win32k Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00225,
            "epssPercentile": 0.13105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65777",
            "title": "Active Directory Security Feature Bypass Vulnerability",
            "summary": "Inadequate encryption strength in Windows Active Directory allows an authorized attacker to bypass a security feature over a network.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00288,
            "epssPercentile": 0.21003,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65778",
            "title": "Windows Autopilot Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11661,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65779",
            "title": "Windows Autopilot Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11662,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65780",
            "title": "Windows Autopilot Elevation of Privilege Vulnerability",
            "summary": "Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09786,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65781",
            "title": "Windows Autopilot Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09786,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65782",
            "title": "Windows Autopilot Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09786,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65783",
            "title": "Windows Autopilot Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09787,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65784",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00299,
            "epssPercentile": 0.22201,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65785",
            "title": "Windows DHCP Client Denial of Service Vulnerability",
            "summary": "Uncontrolled resource consumption in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00378,
            "epssPercentile": 0.30924,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65786",
            "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65787",
            "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.2356,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65788",
            "title": "Desktop Window Manager Elevation of Privilege Vulnerability",
            "summary": "Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01676,
            "epssPercentile": 0.75331,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65790",
            "title": "Windows Message Queuing Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15007,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65794",
            "title": "Windows SMB Client Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00651,
            "epssPercentile": 0.48924,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65795",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17627,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65797",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17582,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65798",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17628,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65799",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00253,
            "epssPercentile": 0.16631,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-65814",
            "title": "Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00252,
            "epssPercentile": 0.16578,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66799",
            "title": "Windows Key Guard Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00269,
            "epssPercentile": 0.18868,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66804",
            "title": "Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.05309,
            "epssPercentile": 0.92057,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-6726",
            "title": "An information leakage vulnerability in the TCG TPM 2.0 reference code.",
            "summary": "An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key. See also TCG VRT0010.",
            "score": 7.9,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00215,
            "epssPercentile": 0.11783,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-6727",
            "title": "CVE-2026-6727",
            "summary": "A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with access to the TPM command interface may be able to exploit timing differences to recover information that could allow decryption of ciphertexts encrypted to TPM-managed RSA keys, including the RSA Endorsement Key (EK), including import blobs, credential blobs, and session salts. Under certain conditi",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00203,
            "epssPercentile": 0.10248,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-68820",
            "title": "Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability",
            "summary": "Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2026-08-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.06184,
            "epssPercentile": 0.93023,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2026-08-25 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70304",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00316,
            "epssPercentile": 0.24068,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70307",
            "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00322,
            "epssPercentile": 0.24811,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70330",
            "title": "Windows DNS Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00316,
            "epssPercentile": 0.24068,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70344",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23562,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70345",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.15005,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70346",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70347",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23517,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-70348",
            "title": "Windows Management Services Denial of Service Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00425,
            "epssPercentile": 0.35642,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [
        {
          "title": "Certain games can become unresponsive",
          "status": "workaround-available",
          "summary": "Microsoft associates reported crashes, hangs or restarts with some RGB-related components that install the inpoutx64 driver."
        }
      ],
      "deployment_effects": [
        "Assess systems that use affected RGB-related peripherals or internal components before broad deployment.",
        "The vendor workaround changes the Windows registry and requires a restart, so it should follow normal change-control and rollback practice.",
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "This record covers one Windows 11 cumulative release, not the full Microsoft August product or CVE set.",
        "The complete Security Update Guide relationship set was not imported.",
        "Applicability to a specific RGB device or driver installation requires local assessment.",
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial August security update publication."
        },
        {
          "revision": 2,
          "observed_at": "2026-08-20",
          "summary": "Microsoft added the RGB-related game issue."
        },
        {
          "revision": 3,
          "observed_at": "2026-08-21",
          "summary": "Microsoft added a registry-based workaround for the same canonical KB record."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Exploitation reported by the vendor source",
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-62815",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-windows-kb5123273",
      "slug": "microsoft-2026-08-windows-kb5123273",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5123273",
      "title": "Deploy Microsoft Windows security update KB5123273",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5123273",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows 11 Version 25H2 for ARM64-based Systems, plus 1 more",
      "platform": "Windows",
      "release_version": "10.0.26100.9165, 10.0.26200.9165",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows 11 Version 25H2 for ARM64-based Systems, plus 1 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-6726"
        ],
        "details": [
          {
            "id": "CVE-2026-6726",
            "title": "An information leakage vulnerability in the TCG TPM 2.0 reference code.",
            "summary": "An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key. See also TCG VRT0010.",
            "score": 7.9,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00215,
            "epssPercentile": 0.11783,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.9,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-6726",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-windows-kb5123303",
      "slug": "microsoft-2026-08-windows-kb5123303",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5123303",
      "title": "Deploy Microsoft Windows security update KB5123303",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5123303",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Windows Server 2022, Windows Server 2022 (Server Core installation)",
      "platform": "Windows",
      "release_version": "10.0.20348.5499",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Windows Server 2022, Windows Server 2022 (Server Core installation).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 3,
        "ids": [
          "CVE-2026-66799",
          "CVE-2026-6726",
          "CVE-2026-6727"
        ],
        "details": [
          {
            "id": "CVE-2026-66799",
            "title": "Windows Key Guard Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00269,
            "epssPercentile": 0.18868,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-6726",
            "title": "An information leakage vulnerability in the TCG TPM 2.0 reference code.",
            "summary": "An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key. See also TCG VRT0010.",
            "score": 7.9,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00215,
            "epssPercentile": 0.11783,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-6727",
            "title": "CVE-2026-6727",
            "summary": "A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with access to the TPM command interface may be able to exploit timing differences to recover information that could allow decryption of ciphertexts encrypted to TPM-managed RSA keys, including the RSA Endorsement Key (EK), including import blobs, credential blobs, and session salts. Under certain conditi",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00203,
            "epssPercentile": 0.10248,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.9,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-6726",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-windows-kb5123607",
      "slug": "microsoft-2026-08-windows-kb5123607",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5123607",
      "title": "Deploy Microsoft Windows security update KB5123607",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5123607",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows 11 Version 25H2 for ARM64-based Systems, plus 1 more",
      "platform": "Windows",
      "release_version": "10.0.26100.9165, 10.0.26200.9165",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows 11 Version 25H2 for ARM64-based Systems, plus 1 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-6726"
        ],
        "details": [
          {
            "id": "CVE-2026-6726",
            "title": "An information leakage vulnerability in the TCG TPM 2.0 reference code.",
            "summary": "An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key. See also TCG VRT0010.",
            "score": 7.9,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00215,
            "epssPercentile": 0.11783,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.9,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-6726",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-windows-msrc-2026-08-windows-11-3-9-windows-app-for-mac",
      "slug": "microsoft-2026-08-windows-msrc-2026-08-windows-11-3-9-windows-app-for-mac",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-08-windows-11-3-9",
      "title": "Deploy Microsoft Windows update for Windows App for Mac",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://msrc.microsoft.com/update-guide/releaseNote/2026-Aug",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Windows App for Mac",
      "platform": "Windows",
      "release_version": "11.3.9",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows App for Mac.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-69550"
        ],
        "details": [
          {
            "id": "CVE-2026-69550",
            "title": "Windows App for Mac Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00651,
            "epssPercentile": 0.48923,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 6.5,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-69550",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "microsoft-2026-08-windows-msrc-2026-08-windows-release-notes-windows-app-client-for-windows-desktop",
      "slug": "microsoft-2026-08-windows-msrc-2026-08-windows-release-notes-windows-app-client-for-windows-desktop",
      "cycle_id": "2026-08",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2026-08-windows-release-notes",
      "title": "Deploy Microsoft Windows update for Windows App Client for Windows Desktop",
      "source_title": "2026-08 Microsoft Security Update Guide",
      "source_url": "https://learn.microsoft.com/en-us/windows-app/whats-new?toc=admins%2Ftoc.json&tabs=windows",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Windows App Client for Windows Desktop",
      "platform": "Windows",
      "release_version": "2.0.1193.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows App Client for Windows Desktop.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-59133"
        ],
        "details": [
          {
            "id": "CVE-2026-59133",
            "title": "Microsoft High Performance Computing (HPC) Pack Elevation of Privilege Vulnerability",
            "summary": "Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privileges over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00941,
            "epssPercentile": 0.58663,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-59133",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "adobe-apsb26-123",
      "slug": "adobe-apsb26-123",
      "cycle_id": "2026-08",
      "vendor_id": "adobe",
      "vendor_name": "Adobe",
      "source_id": "adobe-security-bulletins",
      "advisory_id": "APSB26-123",
      "title": "Update Adobe Campaign Classic to the fixed Adobe release",
      "source_title": "APSB26-123 : Security update available for Adobe Campaign Classic",
      "source_url": "https://helpx.adobe.com/security/products/campaign/apsb26-123.html",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Adobe Campaign Classic",
      "platform": "Windows, Linux",
      "release_version": "ACC v7 7.4.4 build 9400",
      "action_type": "upgrade-release",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 10.0; Adobe priority 1",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "Adobe published APSB26-123 on Patch Tuesday for Adobe Campaign Classic. The bulletin links 3 CVEs and provides fixed release guidance.",
      "cves": {
        "state": "complete-for-advisory",
        "vendor_stated_count": 3,
        "ids": [
          "CVE-2026-27302",
          "CVE-2026-48381",
          "CVE-2026-71398"
        ],
        "details": [
          {
            "id": "CVE-2026-27302",
            "title": "Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)",
            "summary": "Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.",
            "score": 10,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00712,
            "epssPercentile": 0.51304,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "ACC v7: 7.4.4 build 9400",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48381",
            "title": "Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)",
            "summary": "Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interactio",
            "score": 9,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00582,
            "epssPercentile": 0.45658,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "ACC v7: 7.4.4 build 9400",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-71398",
            "title": "Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)",
            "summary": "Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.",
            "score": 10,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00794,
            "epssPercentile": 0.54045,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "ACC v7: 7.4.4 build 9400",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update path and test the fixed release against managed plug-ins, workflows and file formats before broad deployment."
      ],
      "data_gaps": [
        "Restart requirements are not asserted unless the reviewed bulletin states them explicitly."
      ],
      "provenance": [
        {
          "field": "advisory_identity_and_release",
          "source_path": "adobe-bulletin/solution",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships",
          "source_path": "adobe-bulletin/vulnerability-details",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial APSB26-123 publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The bulletin identity, release date, fixed versions, platforms, vendor signals and complete public CVE list were generated from the official Adobe bulletin and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 10,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-71398",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "adobe-apsb26-90",
      "slug": "adobe-apsb26-90",
      "cycle_id": "2026-08",
      "vendor_id": "adobe",
      "vendor_name": "Adobe",
      "source_id": "adobe-security-bulletins",
      "advisory_id": "APSB26-90",
      "title": "Update Adobe ColdFusion to the fixed Adobe release",
      "source_title": "APSB26-90 : Security update available for Adobe ColdFusion",
      "source_url": "https://helpx.adobe.com/security/products/coldfusion/apsb26-90.html",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Adobe ColdFusion",
      "platform": "All",
      "release_version": "2025.0.12, 2023.0.23",
      "action_type": "upgrade-release",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 10.0; Adobe priority 1",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "Adobe published APSB26-90 on Patch Tuesday for Adobe ColdFusion. The bulletin links 16 CVEs and provides fixed release guidance.",
      "cves": {
        "state": "complete-for-advisory",
        "vendor_stated_count": 16,
        "ids": [
          "CVE-2026-21273",
          "CVE-2026-21279",
          "CVE-2026-25652",
          "CVE-2026-34635",
          "CVE-2026-48273",
          "CVE-2026-48362",
          "CVE-2026-48375",
          "CVE-2026-48376",
          "CVE-2026-48384",
          "CVE-2026-48386",
          "CVE-2026-48440",
          "CVE-2026-71383",
          "CVE-2026-71384",
          "CVE-2026-71385",
          "CVE-2026-71386",
          "CVE-2026-71387"
        ],
        "details": [
          {
            "id": "CVE-2026-21273",
            "title": "ColdFusion | Improper Input Validation (CWE-20)",
            "summary": "is affected by an Improper Input Validation vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain unauthorized read and write access. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.",
            "score": 8.7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00564,
            "epssPercentile": 0.44809,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "2025.0.12; 2023.0.23",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-21279",
            "title": "ColdFusion | Improper Input Validation (CWE-20)",
            "summary": "is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and limited write access. Exploitation of this issue does not require user interaction.",
            "score": 8.2,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00507,
            "epssPercentile": 0.41481,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "2025.0.12; 2023.0.23",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-25652",
            "title": "ColdFusion | Incorrect Authorization (CWE-863)",
            "summary": "is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain unauthorized read and write access. Exploitation of this issue does not require user interaction.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00143,
            "epssPercentile": 0.03873,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "2025.0.12; 2023.0.23",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-34635",
            "title": "ColdFusion | Use of Hard-coded Cryptographic Key (CWE-321)",
            "summary": "is affected by a Use of Hard-coded Cryptographic Key vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of this issue does not require user interaction. Scope is changed.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00185,
            "epssPercentile": 0.08193,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "2025.0.12; 2023.0.23",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48273",
            "title": null,
            "summary": null,
            "score": null,
            "version": null,
            "severity": null,
            "cvssSource": null,
            "wild": false,
            "wildDetail": null,
            "publicExploit": null,
            "publicExploitDetail": null,
            "epss": null,
            "epssPercentile": null,
            "epssDate": null,
            "attackVector": null,
            "attackComplexity": null,
            "privilegesRequired": null,
            "userInteraction": null,
            "patchState": null,
            "fixed": null,
            "urgency": null,
            "urgencyReason": null,
            "confidence": null
          },
          {
            "id": "CVE-2026-48362",
            "title": "ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)",
            "summary": "ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.",
            "score": 10,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.04312,
            "epssPercentile": 0.9051,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "2025.0.12; 2023.0.23",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48375",
            "title": "ColdFusion | Incorrect Authorization (CWE-863)",
            "summary": "ColdFusion is affected by an Incorrect Authorization vulnerability that could result in an application denial-of-service. A low-privileged attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0058,
            "epssPercentile": 0.45559,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "2025.0.12; 2023.0.23",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48376",
            "title": "ColdFusion | Improper Encoding or Escaping of Output (CWE-116)",
            "summary": "is affected by an Improper Encoding or Escaping of Output vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized write access, causing a limited disruption to availability. Exploitation of this issue does not require user interaction.",
            "score": 5.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.15479,
            "epssPercentile": 0.96569,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "2025.0.12; 2023.0.23",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48384",
            "title": "ColdFusion | Improper Input Validation (CWE-20)",
            "summary": "ColdFusion is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker with high privileges could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.",
            "score": 4.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00702,
            "epssPercentile": 0.50929,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "2025.0.12; 2023.0.23",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48386",
            "title": "ColdFusion | Use of a Broken or Risky Cryptographic Algorithm (CWE-327)",
            "summary": "ColdFusion is affected by a Use of a Broken or Risky Cryptographic Algorithm vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue does not require user interaction.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00808,
            "epssPercentile": 0.54502,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "2025.0.12; 2023.0.23",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48440",
            "title": "ColdFusion | Heap-based Buffer Overflow (CWE-122)",
            "summary": "ColdFusion is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00655,
            "epssPercentile": 0.49073,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "2025.0.12; 2023.0.23",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-71383",
            "title": "ColdFusion | Incorrect Authorization (CWE-863)",
            "summary": "is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized read and write access, causing a limited disruption to availability. Exploitation of this issue does not require user interaction.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00247,
            "epssPercentile": 0.15943,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "2025.0.12; 2023.0.23",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-71384",
            "title": "ColdFusion | Incorrect Authorization (CWE-863)",
            "summary": "is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access, potentially resulting in an application denial-of-service condition. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require",
            "score": 9.6,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00385,
            "epssPercentile": 0.31652,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "2025.0.12; 2023.0.23",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-71385",
            "title": null,
            "summary": null,
            "score": null,
            "version": null,
            "severity": null,
            "cvssSource": null,
            "wild": false,
            "wildDetail": null,
            "publicExploit": null,
            "publicExploitDetail": null,
            "epss": null,
            "epssPercentile": null,
            "epssDate": null,
            "attackVector": null,
            "attackComplexity": null,
            "privilegesRequired": null,
            "userInteraction": null,
            "patchState": null,
            "fixed": null,
            "urgency": null,
            "urgencyReason": null,
            "confidence": null
          },
          {
            "id": "CVE-2026-71386",
            "title": "ColdFusion | Cross-site Scripting (XSS) (CWE-79)",
            "summary": "is affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.06945,
            "epssPercentile": 0.93673,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "2025.0.12; 2023.0.23",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-71387",
            "title": "ColdFusion | Incorrect Authorization (CWE-863)",
            "summary": "ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00286,
            "epssPercentile": 0.20824,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "2025.0.12; 2023.0.23",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update path and test the fixed release against managed plug-ins, workflows and file formats before broad deployment."
      ],
      "data_gaps": [
        "Restart requirements are not asserted unless the reviewed bulletin states them explicitly."
      ],
      "provenance": [
        {
          "field": "advisory_identity_and_release",
          "source_path": "adobe-bulletin/solution",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships",
          "source_path": "adobe-bulletin/vulnerability-details",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial APSB26-90 publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The bulletin identity, release date, fixed versions, platforms, vendor signals and complete public CVE list were generated from the official Adobe bulletin and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 10,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-48362",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "adobe-apsb26-111",
      "slug": "adobe-apsb26-111",
      "cycle_id": "2026-08",
      "vendor_id": "adobe",
      "vendor_name": "Adobe",
      "source_id": "adobe-security-bulletins",
      "advisory_id": "APSB26-111",
      "title": "Update Content Credentials SDK to the fixed Adobe release",
      "source_title": "APSB26-111 : Security update available for Content Credentials SDK",
      "source_url": "https://helpx.adobe.com/security/products/content-authenticity-sdk/apsb26-111.html",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Content Credentials SDK",
      "platform": "All",
      "release_version": "c2pa-v0.90.6, c2patool-v0.27.6, @contentauth/c2pa-web@0.12.1",
      "action_type": "upgrade-release",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 7.5; Adobe priority 3",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "Adobe published APSB26-111 on Patch Tuesday for Content Credentials SDK. The bulletin links 15 CVEs and provides fixed release guidance.",
      "cves": {
        "state": "complete-for-advisory",
        "vendor_stated_count": 15,
        "ids": [
          "CVE-2026-47922",
          "CVE-2026-48387",
          "CVE-2026-48434",
          "CVE-2026-48435",
          "CVE-2026-48436",
          "CVE-2026-48437",
          "CVE-2026-48438",
          "CVE-2026-48439",
          "CVE-2026-48442",
          "CVE-2026-48443",
          "CVE-2026-48444",
          "CVE-2026-48445",
          "CVE-2026-48446",
          "CVE-2026-71389",
          "CVE-2026-71390"
        ],
        "details": [
          {
            "id": "CVE-2026-47922",
            "title": "CAI Content Credentials | Server-Side Request Forgery (SSRF) (CWE-918)",
            "summary": "CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.",
            "score": 4.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00441,
            "epssPercentile": 0.36978,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "c2pa-v0.90.6; c2patool-v0.27.6; @contentauth/c2pa-web@0.12.1",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48387",
            "title": "CAI Content Credentials | Integer Overflow or Wraparound (CWE-190)",
            "summary": "CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00165,
            "epssPercentile": 0.05972,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "c2pa-v0.90.6; c2patool-v0.27.6; @contentauth/c2pa-web@0.12.1",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48434",
            "title": "CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)",
            "summary": "CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00165,
            "epssPercentile": 0.05972,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "c2pa-v0.90.6; c2patool-v0.27.6; @contentauth/c2pa-web@0.12.1",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48435",
            "title": "CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191)",
            "summary": "CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00165,
            "epssPercentile": 0.05972,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "c2pa-v0.90.6; c2patool-v0.27.6; @contentauth/c2pa-web@0.12.1",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48436",
            "title": "CAI Content Credentials | Improper Input Validation (CWE-20)",
            "summary": "CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00389,
            "epssPercentile": 0.32175,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "c2pa-v0.90.6; c2patool-v0.27.6; @contentauth/c2pa-web@0.12.1",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48437",
            "title": "CAI Content Credentials | Improper Certificate Validation (CWE-295)",
            "summary": "CAI Content Credentials is affected by an Improper Certificate Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00103,
            "epssPercentile": 0.01082,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "c2pa-v0.90.6; c2patool-v0.27.6; @contentauth/c2pa-web@0.12.1",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48438",
            "title": "CAI Content Credentials | NULL Pointer Dereference (CWE-476)",
            "summary": "CAI Content Credentials is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00508,
            "epssPercentile": 0.41547,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "c2pa-v0.90.6; c2patool-v0.27.6; @contentauth/c2pa-web@0.12.1",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48439",
            "title": "CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)",
            "summary": "CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00508,
            "epssPercentile": 0.41548,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "c2pa-v0.90.6; c2patool-v0.27.6; @contentauth/c2pa-web@0.12.1",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48442",
            "title": "CAI Content Credentials | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)",
            "summary": "CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Arbitrary file system read. An attacker could leverage this vulnerability to gain unauthorized read access to files or directories outside the intended restrictions. Exploitation of this issue does not require user interaction. Scope is changed.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00242,
            "epssPercentile": 0.15247,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "c2pa-v0.90.6; c2patool-v0.27.6; @contentauth/c2pa-web@0.12.1",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48443",
            "title": "CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)",
            "summary": "CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11749,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "c2pa-v0.90.6; c2patool-v0.27.6; @contentauth/c2pa-web@0.12.1",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48444",
            "title": "CAI Content Credentials | Integer Overflow or Wraparound (CWE-190)",
            "summary": "CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00224,
            "epssPercentile": 0.1299,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "c2pa-v0.90.6; c2patool-v0.27.6; @contentauth/c2pa-web@0.12.1",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48445",
            "title": "CAI Content Credentials | Integer Overflow or Wraparound (CWE-190)",
            "summary": "CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11749,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "c2pa-v0.90.6; c2patool-v0.27.6; @contentauth/c2pa-web@0.12.1",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48446",
            "title": "CAI Content Credentials | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)",
            "summary": "CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or intera",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00242,
            "epssPercentile": 0.1526,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "c2pa-v0.90.6; c2patool-v0.27.6; @contentauth/c2pa-web@0.12.1",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-71389",
            "title": "CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191)",
            "summary": "CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00153,
            "epssPercentile": 0.04774,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "c2pa-v0.90.6; c2patool-v0.27.6; @contentauth/c2pa-web@0.12.1",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-71390",
            "title": "CAI Content Credentials | Improper Input Validation (CWE-20)",
            "summary": "CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized limited write access. Exploitation of this issue does not require user interaction.",
            "score": 4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00155,
            "epssPercentile": 0.04989,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "c2pa-v0.90.6; c2patool-v0.27.6; @contentauth/c2pa-web@0.12.1",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update path and test the fixed release against managed plug-ins, workflows and file formats before broad deployment."
      ],
      "data_gaps": [
        "Restart requirements are not asserted unless the reviewed bulletin states them explicitly."
      ],
      "provenance": [
        {
          "field": "advisory_identity_and_release",
          "source_path": "adobe-bulletin/solution",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships",
          "source_path": "adobe-bulletin/vulnerability-details",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial APSB26-111 publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The bulletin identity, release date, fixed versions, platforms, vendor signals and complete public CVE list were generated from the official Adobe bulletin and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.5,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-48439",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "adobe-apsb26-94",
      "slug": "adobe-apsb26-94",
      "cycle_id": "2026-08",
      "vendor_id": "adobe",
      "vendor_name": "Adobe",
      "source_id": "adobe-security-bulletins",
      "advisory_id": "APSB26-94",
      "title": "Update Adobe Lightroom Classic to the fixed Adobe release",
      "source_title": "APSB26-94 : Security update available for Adobe Lightroom Classic",
      "source_url": "https://helpx.adobe.com/security/products/lightroom/apsb26-94.html",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Adobe Lightroom Classic",
      "platform": "All",
      "release_version": "15.5",
      "action_type": "upgrade-release",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 8.6; Adobe priority 3",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "Adobe published APSB26-94 on Patch Tuesday for Adobe Lightroom Classic. The bulletin links 11 CVEs and provides fixed release guidance.",
      "cves": {
        "state": "complete-for-advisory",
        "vendor_stated_count": 11,
        "ids": [
          "CVE-2026-47940",
          "CVE-2026-48397",
          "CVE-2026-48404",
          "CVE-2026-48405",
          "CVE-2026-48406",
          "CVE-2026-48407",
          "CVE-2026-48408",
          "CVE-2026-48409",
          "CVE-2026-48410",
          "CVE-2026-48441",
          "CVE-2026-48447"
        ],
        "details": [
          {
            "id": "CVE-2026-47940",
            "title": "Lightroom Classic | Integer Overflow or Wraparound (CWE-190)",
            "summary": "Lightroom Classic is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00181,
            "epssPercentile": 0.07771,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "15.5",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48397",
            "title": "Lightroom Classic | Deserialization of Untrusted Data (CWE-502)",
            "summary": "Lightroom Classic is affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.",
            "score": 8.6,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00547,
            "epssPercentile": 0.43857,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "15.5",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48404",
            "title": "Lightroom Classic | Out-of-bounds Write (CWE-787)",
            "summary": "Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00158,
            "epssPercentile": 0.05317,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "15.5",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48405",
            "title": "Lightroom Classic | Out-of-bounds Write (CWE-787)",
            "summary": "Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00158,
            "epssPercentile": 0.05317,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "15.5",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48406",
            "title": "Lightroom Classic | Out-of-bounds Write (CWE-787)",
            "summary": "Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00158,
            "epssPercentile": 0.05316,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "15.5",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48407",
            "title": "Lightroom Classic | Out-of-bounds Write (CWE-787)",
            "summary": "Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00158,
            "epssPercentile": 0.05317,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "15.5",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48408",
            "title": "Lightroom Classic | Out-of-bounds Write (CWE-787)",
            "summary": "Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00158,
            "epssPercentile": 0.05316,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "15.5",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48409",
            "title": "Lightroom Classic | Out-of-bounds Write (CWE-787)",
            "summary": "Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00158,
            "epssPercentile": 0.05316,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "15.5",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48410",
            "title": "Lightroom Classic | Out-of-bounds Write (CWE-787)",
            "summary": "Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00158,
            "epssPercentile": 0.05317,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "15.5",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48441",
            "title": "Lightroom Classic | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)",
            "summary": "Lightroom Classic is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.",
            "score": 8.6,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00193,
            "epssPercentile": 0.08977,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "15.5",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48447",
            "title": "Lightroom Classic | Incorrect Authorization (CWE-863)",
            "summary": "Lightroom Classic is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.",
            "score": 7.7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00144,
            "epssPercentile": 0.03994,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "15.5",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update path and test the fixed release against managed plug-ins, workflows and file formats before broad deployment."
      ],
      "data_gaps": [
        "Restart requirements are not asserted unless the reviewed bulletin states them explicitly."
      ],
      "provenance": [
        {
          "field": "advisory_identity_and_release",
          "source_path": "adobe-bulletin/solution",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships",
          "source_path": "adobe-bulletin/vulnerability-details",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial APSB26-94 publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The bulletin identity, release date, fixed versions, platforms, vendor signals and complete public CVE list were generated from the official Adobe bulletin and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.6,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-48441",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "adobe-apsb26-92",
      "slug": "adobe-apsb26-92",
      "cycle_id": "2026-08",
      "vendor_id": "adobe",
      "vendor_name": "Adobe",
      "source_id": "adobe-security-bulletins",
      "advisory_id": "APSB26-92",
      "title": "Update Adobe Commerce to the fixed Adobe release",
      "source_title": "APSB26-92 : Security update available for Adobe Commerce",
      "source_url": "https://helpx.adobe.com/security/products/magento/apsb26-92.html",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "Adobe Commerce",
      "platform": "All",
      "release_version": "2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug, 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug, 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug",
      "action_type": "upgrade-release",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 9.1; Adobe priority 2",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "Adobe published APSB26-92 on Patch Tuesday for Adobe Commerce. The bulletin links 7 CVEs and provides fixed release guidance.",
      "cves": {
        "state": "complete-for-advisory",
        "vendor_stated_count": 7,
        "ids": [
          "CVE-2026-48411",
          "CVE-2026-48412",
          "CVE-2026-48413",
          "CVE-2026-48414",
          "CVE-2026-48415",
          "CVE-2026-48416",
          "CVE-2026-71362"
        ],
        "details": [
          {
            "id": "CVE-2026-48411",
            "title": "Adobe Commerce | Incorrect Authorization (CWE-863)",
            "summary": "Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00771,
            "epssPercentile": 0.53307,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug; 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug; 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48412",
            "title": "Adobe Commerce | Incorrect Authorization (CWE-863)",
            "summary": "Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker with high privileges could exploit this vulnerability to gain elevated access to restricted resources. Exploitation of this issue does not require user interaction.",
            "score": 2.7,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00394,
            "epssPercentile": 0.3264,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug; 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug; 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48413",
            "title": "Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)",
            "summary": "Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.",
            "score": 8.7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00628,
            "epssPercentile": 0.47873,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug; 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug; 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48414",
            "title": "Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)",
            "summary": "Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Exploit depends on conditio",
            "score": 7.7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43108,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug; 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug; 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48415",
            "title": "Adobe Commerce | Incorrect Authorization (CWE-863)",
            "summary": "Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access, causing a limited disruption to availability. Exploitation of this issue does not require user interaction.",
            "score": 7.6,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00349,
            "epssPercentile": 0.27858,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug; 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug; 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-48416",
            "title": "Adobe Commerce | Incorrect Authorization (CWE-863)",
            "summary": "Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00495,
            "epssPercentile": 0.4073,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug; 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug; 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-71362",
            "title": "Adobe Commerce | Incorrect Authorization (CWE-863)",
            "summary": "Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.",
            "score": 9.1,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.25136,
            "epssPercentile": 0.97784,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug; 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug; 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update path and test the fixed release against managed plug-ins, workflows and file formats before broad deployment."
      ],
      "data_gaps": [
        "Restart requirements are not asserted unless the reviewed bulletin states them explicitly."
      ],
      "provenance": [
        {
          "field": "advisory_identity_and_release",
          "source_path": "adobe-bulletin/solution",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships",
          "source_path": "adobe-bulletin/vulnerability-details",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Initial APSB26-92 publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The bulletin identity, release date, fixed versions, platforms, vendor signals and complete public CVE list were generated from the official Adobe bulletin and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-71362",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative ring before broad deployment."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-08-3771065",
      "slug": "sap-2026-08-3771065",
      "cycle_id": "2026-08",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3771065",
      "title": "Assess and apply SAP security advisory 3771065",
      "source_title": "[CVE-2026-58231] Improper Authorization in SAP Commerce Cloud (Data Hub Adapter) Product - SAP Commerce Cloud (Data Hub Adapter) | Version(s) - COM_CLOUD 2211, 2211-JDK21",
      "source_url": "https://me.sap.com/notes/3771065",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "SAP Commerce Cloud (Data Hub Adapter)",
      "platform": "SAP",
      "release_version": "COM_CLOUD 2211, 2211-JDK21",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 10.0",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3771065 in its 2026-08 Security Patch Day release for SAP Commerce Cloud (Data Hub Adapter). The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-58231"
        ],
        "details": [
          {
            "id": "CVE-2026-58231",
            "title": "Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)",
            "summary": "SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.",
            "score": 10,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0171,
            "epssPercentile": 0.75831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 10,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-58231",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-08-3765948",
      "slug": "sap-2026-08-3765948",
      "cycle_id": "2026-08",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3765948",
      "title": "Assess and apply SAP security advisory 3765948",
      "source_title": "[CVE-2026-44772] Code Injection vulnerability in SAP Manufacturing Integration and Intelligence Product - SAP Manufacturing Integration and Intelligence | Version(s) - XMII 15.4, 15.5, MII_ADMIN 15.4, 15.5",
      "source_url": "https://me.sap.com/notes/3765948",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "SAP Manufacturing Integration and Intelligence",
      "platform": "SAP",
      "release_version": "XMII 15.4, 15.5, MII_ADMIN 15.4, 15.5",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 9.9",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3765948 in its 2026-08 Security Patch Day release for SAP Manufacturing Integration and Intelligence. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-44772"
        ],
        "details": [
          {
            "id": "CVE-2026-44772",
            "title": null,
            "summary": null,
            "score": null,
            "version": null,
            "severity": null,
            "cvssSource": null,
            "wild": false,
            "wildDetail": null,
            "publicExploit": null,
            "publicExploitDetail": null,
            "epss": null,
            "epssPercentile": null,
            "epssDate": null,
            "attackVector": null,
            "attackComplexity": null,
            "privilegesRequired": null,
            "userInteraction": null,
            "patchState": null,
            "fixed": null,
            "urgency": null,
            "urgencyReason": null,
            "confidence": null
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.9,
        "max_cvss_version": null,
        "max_cvss_cve": null,
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-08-3714806",
      "slug": "sap-2026-08-3714806",
      "cycle_id": "2026-08",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3714806",
      "title": "Assess and apply SAP security advisory 3714806",
      "source_title": "[CVE-2026-34265] Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform Product - SAP NetWeaver and ABAP Platform | Version(s) - KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.22EXT2, 7.22EXT3, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16 9.18, 9.19, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19",
      "source_url": "https://me.sap.com/notes/3714806",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "SAP NetWeaver and ABAP Platform",
      "platform": "SAP",
      "release_version": "KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.22EXT2, 7.22EXT3, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16 9.18, 9.19, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 9.8",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3714806 in its 2026-08 Security Patch Day release for SAP NetWeaver and ABAP Platform. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-34265"
        ],
        "details": [
          {
            "id": "CVE-2026-34265",
            "title": "Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform",
            "summary": "SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This vulnerability could potentially disclose sensitive system information or crash the system, leading to a high impact on the confidentiality, integrity, and availability of the application.",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0057,
            "epssPercentile": 0.45089,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-34265",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-08-3758900",
      "slug": "sap-2026-08-3758900",
      "cycle_id": "2026-08",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3758900",
      "title": "Assess and apply SAP security advisory 3758900",
      "source_title": "[CVE-2026-44758] Code Injection vulnerability in Manufacturing Integration and Intelligence Product - SAP Manufacturing Integration and Intelligence | Version(s) - XMII 15.4, 15.5",
      "source_url": "https://me.sap.com/notes/3758900",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "SAP Manufacturing Integration and Intelligence",
      "platform": "SAP",
      "release_version": "XMII 15.4, 15.5",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 9.1",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3758900 in its 2026-08 Security Patch Day release for SAP Manufacturing Integration and Intelligence. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-44758"
        ],
        "details": [
          {
            "id": "CVE-2026-44758",
            "title": "Code Injection vulnerability in Manufacturing Integration and Intelligence",
            "summary": "SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system, resulting in high impact on confidentiality, integrity, and availability of the application.",
            "score": 9.1,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00671,
            "epssPercentile": 0.49709,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-44758",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-08-3772411",
      "slug": "sap-2026-08-3772411",
      "cycle_id": "2026-08",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3772411",
      "title": "Assess and apply SAP security advisory 3772411",
      "source_title": "[CVE-2026-58243] Privilege Escalation vulnerability in SAP ABAP Developer Tools Product - SAP ABAP Developer Tools | Version(s) - SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 816, SAP_BASIS 918, SAP_BASIS 920",
      "source_url": "https://me.sap.com/notes/3772411",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "SAP ABAP Developer Tools",
      "platform": "SAP",
      "release_version": "SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 816, SAP_BASIS 918, SAP_BASIS 920",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "High; CVSS 8.8",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3772411 in its 2026-08 Security Patch Day release for SAP ABAP Developer Tools. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-58243"
        ],
        "details": [
          {
            "id": "CVE-2026-58243",
            "title": "Privilege Escalation vulnerability in SAP ABAP Developer Tools",
            "summary": "SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to execute unauthorized database operations against SAP NetWeaver AS ABAP. Successful exploitation could allow the attacker to read sensitive data, modify application data, and disrupt access for legitimate users, resulting in high impact on confidentiality, integrity, and ava",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00331,
            "epssPercentile": 0.25779,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-58243",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-08-3773203",
      "slug": "sap-2026-08-3773203",
      "cycle_id": "2026-08",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3773203",
      "title": "Assess and apply SAP security advisory 3773203",
      "source_title": "[CVE-2026-42945] Potential buffer overflow vulnerability affects SAP Commerce Cloud in public‑cloud deployments with NGINX Product - SAP Commerce Cloud | Version(s) - COM_CLOUD 2211, 2211-JDK21, DHUB_CLOUD 2211, 2211-JDK21",
      "source_url": "https://me.sap.com/notes/3773203",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "SAP Commerce Cloud",
      "platform": "SAP",
      "release_version": "COM_CLOUD 2211, 2211-JDK21, DHUB_CLOUD 2211, 2211-JDK21",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "High; CVSS 8.1",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3773203 in its 2026-08 Security Patch Day release for SAP Commerce Cloud. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-42945"
        ],
        "details": [
          {
            "id": "CVE-2026-42945",
            "title": "NGINX ngx_http_rewrite_module vulnerability",
            "summary": "NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploi",
            "score": 9.2,
            "version": "4.0",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.68047,
            "epssPercentile": 0.99273,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "R37 < *; 1.31.0 < *",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path and a public exploit reference; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.2,
        "max_cvss_version": "4.0",
        "max_cvss_cve": "CVE-2026-42945",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-08-3756565",
      "slug": "sap-2026-08-3756565",
      "cycle_id": "2026-08",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3756565",
      "title": "Assess and apply SAP security advisory 3756565",
      "source_title": "[CVE-2026-66763] Credentials disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Server) Product - SAP BusinessObjects Business Intelligence Platform (Central Management Server) | Version(s) - ENTERPRISE 430, 2025, 2027",
      "source_url": "https://me.sap.com/notes/3756565",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "SAP BusinessObjects Business Intelligence Platform (Central Management Server)",
      "platform": "SAP",
      "release_version": "ENTERPRISE 430, 2025, 2027",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "High; CVSS 7.9",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3756565 in its 2026-08 Security Patch Day release for SAP BusinessObjects Business Intelligence Platform (Central Management Server). The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-66763"
        ],
        "details": [
          {
            "id": "CVE-2026-66763",
            "title": "Credentials disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Server)",
            "summary": "SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic key. An attacker with high privileges and local access to the server could retrieve these objects and decrypt the stored credentials. Successful exploitation could allow the attacker to obtain sensitive authentication data and modify protected information, resulting in ",
            "score": 7.9,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00131,
            "epssPercentile": 0.03035,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.9,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-66763",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-08-3773304",
      "slug": "sap-2026-08-3773304",
      "cycle_id": "2026-08",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3773304",
      "title": "Assess and apply SAP security advisory 3773304",
      "source_title": "Update to Security Note released on July 2026 Patch Day: [CVE-2026-58233] Remote Code Execution vulnerability in Enhanced Change and Transport System (CTS+) Attach Tool (ctsattach) | | Product - Enhanced Change and Transport System (CTS+) Attach Tool (ctsattach) | Version(s) - CTS_UPLOAD_CLT 1",
      "source_url": "https://me.sap.com/notes/3773304",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "revised",
      "product": "Enhanced Change and Transport System (CTS+) Attach Tool (ctsattach)",
      "platform": "SAP",
      "release_version": "CTS_UPLOAD_CLT 1",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "High; CVSS 7.6",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3773304 in its 2026-08 Security Patch Day release for Enhanced Change and Transport System (CTS+) Attach Tool (ctsattach). The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-58233"
        ],
        "details": [
          {
            "id": "CVE-2026-58233",
            "title": "Remote Code Execution vulnerability in SAP Change and Transport System Attach Tool (ctsattach)",
            "summary": "SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted archive file which, when processed by the application�s library, can trigger insecure deserialization and lead to remote code execution (RCE) on the system. Successful exploitation requires a victim to process the malicious archive, enabling the attacker to execute the RCE and extract sensitive infor",
            "score": 7.6,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00556,
            "epssPercentile": 0.44348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.6,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-58233",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-08-3759854",
      "slug": "sap-2026-08-3759854",
      "cycle_id": "2026-08",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3759854",
      "title": "Assess and apply SAP security advisory 3759854",
      "source_title": "[CVE-2026-44763] Directory Traversal vulnerability in SAP Manufacturing Integration and Intelligence Product - SAP Manufacturing Integration and Intelligence | Version(s) - XMII 15.4, 15.5",
      "source_url": "https://me.sap.com/notes/3759854",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "SAP Manufacturing Integration and Intelligence",
      "platform": "SAP",
      "release_version": "XMII 15.4, 15.5",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "High; CVSS 7.6",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3759854 in its 2026-08 Security Patch Day release for SAP Manufacturing Integration and Intelligence. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-44763"
        ],
        "details": [
          {
            "id": "CVE-2026-44763",
            "title": "Directory Traversal vulnerability in SAP Manufacturing Integration and Intelligence",
            "summary": "SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploitation also requires a legitimate user to subsequently access the attacker-influenced content and depends on conditions outside the attacker�s control. Successful exploitation could allow files to be written outside the intended directory an",
            "score": 7.6,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00288,
            "epssPercentile": 0.21079,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "HIGH",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.6,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-44763",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-08-3758657",
      "slug": "sap-2026-08-3758657",
      "cycle_id": "2026-08",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3758657",
      "title": "Assess and apply SAP security advisory 3758657",
      "source_title": "[CVE-2026-44765] Missing Authorization Check in SAP Manufacturing Integration and Intelligence Product - SAP Manufacturing Integration and Intelligence | Version(s) - XMII 15.4, 15.5",
      "source_url": "https://me.sap.com/notes/3758657",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "SAP Manufacturing Integration and Intelligence",
      "platform": "SAP",
      "release_version": "XMII 15.4, 15.5",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "High; CVSS 7.3",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3758657 in its 2026-08 Security Patch Day release for SAP Manufacturing Integration and Intelligence. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-44765"
        ],
        "details": [
          {
            "id": "CVE-2026-44765",
            "title": "Missing Authorization Check in SAP Manufacturing Integration and Intelligence",
            "summary": "Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated remote attacker could access scheduling-related application functions without proper authorization validation. Successful exploitation could allow the attacker to retrieve, create, modify, or delete application-managed scheduling data, causing a low impact on confidentiality, integrity, and availab",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00284,
            "epssPercentile": 0.20632,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-44765",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-08-3758910",
      "slug": "sap-2026-08-3758910",
      "cycle_id": "2026-08",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3758910",
      "title": "Assess and apply SAP security advisory 3758910",
      "source_title": "[CVE-2026-44764] Missing Authorization Check in SAP Manufacturing Integration and Intelligence Product - SAP Manufacturing Integration and Intelligence | Version(s) - XMII 15.4, 15.5",
      "source_url": "https://me.sap.com/notes/3758910",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "SAP Manufacturing Integration and Intelligence",
      "platform": "SAP",
      "release_version": "XMII 15.4, 15.5",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "High; CVSS 7.3",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3758910 in its 2026-08 Security Patch Day release for SAP Manufacturing Integration and Intelligence. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-44764"
        ],
        "details": [
          {
            "id": "CVE-2026-44764",
            "title": "Missing Authorization Check in SAP Manufacturing Integration and Intelligence",
            "summary": "Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated attacker could send crafted requests to the Cost Servlet using specific parameter values. If processed by the application, these requests enable access to backend operations. Successful exploitation could allow the attacker to read, create, modify, or delete application-managed business data, resul",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0024,
            "epssPercentile": 0.1506,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-44764",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-08-3786038",
      "slug": "sap-2026-08-3786038",
      "cycle_id": "2026-08",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3786038",
      "title": "Assess and apply SAP security advisory 3786038",
      "source_title": "[CVE-2026-58230] Multiple vulnerabilities in SAP Business AI Platform (Approuter) | | Additional CVEs - CVE-2026-66775, CVE-2026-66778, CVE-2026-66760, CVE-2026-66761, CVE-2026-66777, CVE-2026-66776, CVE-2026-66774, CVE-2026-58237, CVE-2026-58238, CVE-2026-58239 Product - SAP Business AI Platform (Approuter) | Version(s) <23.0.0",
      "source_url": "https://me.sap.com/notes/3786038",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "SAP Business AI Platform (Approuter)",
      "platform": "SAP",
      "release_version": "<23.0.0",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "High; CVSS 7.0",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3786038 in its 2026-08 Security Patch Day release for SAP Business AI Platform (Approuter). The public bulletin links 11 CVEs; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 11,
        "ids": [
          "CVE-2026-58230",
          "CVE-2026-58237",
          "CVE-2026-58238",
          "CVE-2026-58239",
          "CVE-2026-66760",
          "CVE-2026-66761",
          "CVE-2026-66774",
          "CVE-2026-66775",
          "CVE-2026-66776",
          "CVE-2026-66777",
          "CVE-2026-66778"
        ],
        "details": [
          {
            "id": "CVE-2026-58230",
            "title": "Multiple vulnerabilities in SAP Business AI Platform (Approuter)",
            "summary": "SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a specially crafted token to cause sensitive credential material to be sent to an attacker-controlled destination. The attack complexity is high due to non-default preconditions required in the target environment. This results in a high impact on confidentiality and a low impact on ",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00243,
            "epssPercentile": 0.15371,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58237",
            "title": "Multiple vulnerabilities in SAP Business AI Platform (Approuter)",
            "summary": "WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with low privileges could exploit this to access restricted functionality. Successful exploitation could allow the attacker to read sensitive information and perform limited modifications, resulting in a high impact on confidentiality and a low impact on integrity. There is no impact on availability.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00216,
            "epssPercentile": 0.11898,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58238",
            "title": "Multiple vulnerabilities in SAP Business AI Platform (Approuter)",
            "summary": "SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could send specially crafted input that causes the component to crash and restart. Successful exploitation requires specific runtime conditions to be met, making the attack complex to execute. This results in a high impact on availability. There is no impact on confidentiality and integrity.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17572,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-58239",
            "title": "Multiple vulnerabilities in SAP Business AI Platform (Approuter)",
            "summary": "SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker could send specially crafted requests to spoof the tenant context under conditions not fully within their control. Successful exploitation could allow limited access to another tenant's information, resulting in a low impact on confidentiality. There is no impact on integrity and availability.",
            "score": 3.7,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0022,
            "epssPercentile": 0.12428,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66760",
            "title": "Multiple vulnerabilities in SAP Business AI Platform (Approuter)",
            "summary": "SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low privileges, holding a certificate from the same trusted authority with matching subject values, could bypass the identity check. This complexity makes the attack difficult to execute. Successful exploitation could allow impersonation of a trusted internal component, resulting in a high impact on integrity and",
            "score": 6.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0012,
            "epssPercentile": 0.02008,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66761",
            "title": "Multiple vulnerabilities in SAP Business AI Platform (Approuter)",
            "summary": "SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileges could send high volumes of data without consuming responses, causing unbounded memory growth. This results in a low impact on availability. There is no impact on confidentiality and integrity.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00221,
            "epssPercentile": 0.1253,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66774",
            "title": "Multiple vulnerabilities in SAP Business AI Platform (Approuter)",
            "summary": "SAP Approuter does not consistently handle certain error conditions. An attacker with low privileges could exploit this under a non-default configuration. Successful exploitation is highly complex, as it depends on conditions outside the attacker's control. This could result in a low impact on availability. There is no impact on confidentiality and integrity.",
            "score": 3.7,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00222,
            "epssPercentile": 0.12642,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66775",
            "title": "Multiple vulnerabilities in SAP Business AI Platform (Approuter)",
            "summary": "SAP Approuter does not enforce cross-site request forgery protection on the authentication flow by default. An unauthenticated attacker could craft a malicious link and trick a victim into following it. Successful exploitation could allow the attacker to bind the victim's session to an attacker-controlled identity, resulting in a low impact on integrity. There is no impact on confidentiality and availability.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00125,
            "epssPercentile": 0.02469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66776",
            "title": "Multiple vulnerabilities in SAP Business AI Platform (Approuter)",
            "summary": "SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker with low privileges could send a specially crafted request that bypasses the integrity check and loads another user's session context. Successful exploitation requires the attacker to have previously observed matching session values out-of-band, which makes the attack co",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00138,
            "epssPercentile": 0.03487,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66777",
            "title": "Multiple vulnerabilities in SAP Business AI Platform (Approuter)",
            "summary": "SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations. Due to the complexity of the required conditions, an attacker with low privileges could send specially crafted requests to bypass authorization checks and reach protected resources beyond their assigned scope. Successful exploitation could allow the attacker to read sensitive data and perform limited",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00315,
            "epssPercentile": 0.23964,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-66778",
            "title": "Multiple vulnerabilities in SAP Business AI Platform (Approuter)",
            "summary": "SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. An unauthenticated attacker could send a specially crafted request to obtain limited unauthorized access to information. This results in a low impact on confidentiality. There is no impact on integrity and availability.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00234,
            "epssPercentile": 0.14288,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-58230",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-08-3753141",
      "slug": "sap-2026-08-3753141",
      "cycle_id": "2026-08",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3753141",
      "title": "Assess and apply SAP security advisory 3753141",
      "source_title": "[CVE-2026-58248] XML External Entity Injection in SAP BusinessObjects Business Intelligence Product - SAP BusinessObjects Business Intelligence | Version(s) - ENTERPRISE 430, 2025, 2027, ENTERPRISECLIENTTOOLS 430, 2025, 2027",
      "source_url": "https://me.sap.com/notes/3753141",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "SAP BusinessObjects Business Intelligence",
      "platform": "SAP",
      "release_version": "ENTERPRISE 430, 2025, 2027, ENTERPRISECLIENTTOOLS 430, 2025, 2027",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 6.5",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3753141 in its 2026-08 Security Patch Day release for SAP BusinessObjects Business Intelligence. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-58248"
        ],
        "details": [
          {
            "id": "CVE-2026-58248",
            "title": "XML External Entity Injection in SAP BusinessObjects Business Intelligence",
            "summary": "SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to upload a specially crafted spreadsheet file containing malicious external references. When the file is processed as a data source, the affected component resolves these references and exposes the contents of sensitive server-side files within the resulting report. This results in a high impact on confidentiality,",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00281,
            "epssPercentile": 0.20331,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 6.5,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-58248",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-08-3770868",
      "slug": "sap-2026-08-3770868",
      "cycle_id": "2026-08",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3770868",
      "title": "Assess and apply SAP security advisory 3770868",
      "source_title": "[CVE-2026-34480] Improper Output Encoding Vulnerability in SAP Commerce Cloud and SAP Data Hub (Apache Log4j Core) Product - SAP Commerce Cloud and SAP Data Hub (Apache Log4j Core) | Version(s) - COM_CLOUD 2211, 2211-JDK21, DHUB_CLOUD 2211",
      "source_url": "https://me.sap.com/notes/3770868",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "SAP Commerce Cloud and SAP Data Hub (Apache Log4j Core)",
      "platform": "SAP",
      "release_version": "COM_CLOUD 2211, 2211-JDK21, DHUB_CLOUD 2211",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 6.5",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3770868 in its 2026-08 Security Patch Day release for SAP Commerce Cloud and SAP Data Hub (Apache Log4j Core). The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-34480"
        ],
        "details": [
          {
            "id": "CVE-2026-34480",
            "title": "Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters",
            "summary": "Apache Log4j Core's XmlLayout https://logging.apache.org/log4j/2.x/manual/layouts.html#XmlLayout , in versions up to and including 2.25.3, fails to sanitize characters forbidden by the XML 1.0 specification https://www.w3.org/TR/xml/#charsets producing invalid XML output whenever a log message or MDC value contains such characters. The impact depends on the StAX implementation in use: * JRE built-in StAX: Forbidden c",
            "score": 6.9,
            "version": "4.0",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00972,
            "epssPercentile": 0.59695,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 6.9,
        "max_cvss_version": "4.0",
        "max_cvss_cve": "CVE-2026-34480",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-08-3757815",
      "slug": "sap-2026-08-3757815",
      "cycle_id": "2026-08",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3757815",
      "title": "Assess and apply SAP security advisory 3757815",
      "source_title": "[CVE-2026-5598] Potential Information Disclosure vulnerability in SAP Commerce Cloud (Bouncy Castle Java library) Product - SAP Commerce Cloud (Bouncy Castle Java library) | Version(s) - COM_CLOUD 2211, 2211-JDK21",
      "source_url": "https://me.sap.com/notes/3757815",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "SAP Commerce Cloud (Bouncy Castle Java library)",
      "platform": "SAP",
      "release_version": "COM_CLOUD 2211, 2211-JDK21",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 6.5",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3757815 in its 2026-08 Security Patch Day release for SAP Commerce Cloud (Bouncy Castle Java library). The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-5598"
        ],
        "details": [
          {
            "id": "CVE-2026-5598",
            "title": "Non-constant time comparisons risk private key leakage in FrodoKEM.",
            "summary": "Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulnerability is associated with program files FrodoEngine.Java. This issue affects BC-JAVA: from 1.71 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.",
            "score": 8.9,
            "version": "4.0",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00899,
            "epssPercentile": 0.57323,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.9,
        "max_cvss_version": "4.0",
        "max_cvss_cve": "CVE-2026-5598",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-08-3721424",
      "slug": "sap-2026-08-3721424",
      "cycle_id": "2026-08",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3721424",
      "title": "Assess and apply SAP security advisory 3721424",
      "source_title": "[CVE-2026-66779] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP Product - SAP NetWeaver Application Server ABAP | Version(s) - SAP_UI 754, 755, 756, 757, 758, 816, EP-FLP 7.50, SAP_BASIS 731, AJAX-RUNTIME 7.50",
      "source_url": "https://me.sap.com/notes/3721424",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "SAP NetWeaver Application Server ABAP",
      "platform": "SAP",
      "release_version": "SAP_UI 754, 755, 756, 757, 758, 816, EP-FLP 7.50, SAP_BASIS 731, AJAX-RUNTIME 7.50",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 6.3",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3721424 in its 2026-08 Security Patch Day release for SAP NetWeaver Application Server ABAP. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-66779"
        ],
        "details": [
          {
            "id": "CVE-2026-66779",
            "title": "Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP",
            "summary": "Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP, an authenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated victim accesses this link, the injected input is processed and reflected within the DOM on the client side during page rendering, resulting in the execution of malicious content in the victim's browser context. Succes",
            "score": 6.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00201,
            "epssPercentile": 0.10024,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 6.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-66779",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-08-3766473",
      "slug": "sap-2026-08-3766473",
      "cycle_id": "2026-08",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3766473",
      "title": "Assess and apply SAP security advisory 3766473",
      "source_title": "[CVE-2026-66770] SQL Injection vulnerability in SAP Social Intelligence Product - SAP Social Intelligence | Version(s) - S4FND 102, 103, 104, 105, 106, 107, 108, 109",
      "source_url": "https://me.sap.com/notes/3766473",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "SAP Social Intelligence",
      "platform": "SAP",
      "release_version": "S4FND 102, 103, 104, 105, 106, 107, 108, 109",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 6.3",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3766473 in its 2026-08 Security Patch Day release for SAP Social Intelligence. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-66770"
        ],
        "details": [
          {
            "id": "CVE-2026-66770",
            "title": "SQL Injection vulnerability in SAP Social Intelligence",
            "summary": "Due to an SQL Injection vulnerability in SAP Social intelligence, an authenticated attacker could directly inject an SQL DDL (Data Definition Language) string into the underlying database without further authorization. Successful exploitation could allow the attacker to make malicious changes to the database structure, resulting in a low impact to the confidentiality, integrity, and availability of the system.",
            "score": 6.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00157,
            "epssPercentile": 0.05185,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 6.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-66770",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-08-3758318",
      "slug": "sap-2026-08-3758318",
      "cycle_id": "2026-08",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3758318",
      "title": "Assess and apply SAP security advisory 3758318",
      "source_title": "[CVE-2026-58235] Use of Vulnerable Third-Party Component in SAP NetWeaver AS Java (Adobe Document Services) Product - SAP NetWeaver AS Java (Adobe Document Services) | Version(s) - ADSSAP 7.50",
      "source_url": "https://me.sap.com/notes/3758318",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "SAP NetWeaver AS Java (Adobe Document Services)",
      "platform": "SAP",
      "release_version": "ADSSAP 7.50",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 6.3",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3758318 in its 2026-08 Security Patch Day release for SAP NetWeaver AS Java (Adobe Document Services). The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-58235"
        ],
        "details": [
          {
            "id": "CVE-2026-58235",
            "title": "Use of Vulnerable Third-Party Component in SAP NetWeaver AS Java (Adobe Document Services)",
            "summary": "SAP NetWeaver Application Server Java (Adobe Document Service) uses outdated open source cryptographic and data transfer libraries that contain known vulnerabilities addressed in later versions. A low-privileged authenticated attacker could potentially leverage these weaknesses against the affected component, though no specific exploit is currently known. Successful exploitation could result in low impact on confiden",
            "score": 6.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00174,
            "epssPercentile": 0.07017,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 6.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-58235",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-08-3772071",
      "slug": "sap-2026-08-3772071",
      "cycle_id": "2026-08",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3772071",
      "title": "Assess and apply SAP security advisory 3772071",
      "source_title": "[CVE-2026-66771] Cross Site Scripting (XSS) vulnerability in SAPUI5 Product - SAPUI5 | Version(s) - SAP_UI 750, 754, 755, 756, 757, 758, 816, UI_700 200",
      "source_url": "https://me.sap.com/notes/3772071",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "SAPUI5",
      "platform": "SAP",
      "release_version": "SAP_UI 750, 754, 755, 756, 757, 758, 816, UI_700 200",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 6.1",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3772071 in its 2026-08 Security Patch Day release for SAPUI5. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-66771"
        ],
        "details": [
          {
            "id": "CVE-2026-66771",
            "title": "Cross Site Scripting (XSS) vulnerability in SAPUI5",
            "summary": "SAPUI5 allows a key user with content adaptation privileges to inject malicious script content into persisted application changes. When another user subsequently opens the adapted application, the injected script executes in the victim's browser session. Successful exploitation could allow the attacker to access sensitive session data and perform unauthorized actions on behalf of the victim, resulting in a high impac",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00216,
            "epssPercentile": 0.11932,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 6.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-66771",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-08-ghsa-hc5j-q32w-c25v",
      "slug": "sap-2026-08-ghsa-hc5j-q32w-c25v",
      "cycle_id": "2026-08",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "GHSA-hc5j-q32w-c25v",
      "title": "Assess and apply SAP security advisory GHSA-hc5j-q32w-c25v",
      "source_title": "[CVE-2026-66773] Server-controlled `__next` URL is not checking cross-origin Product - No SAP products impacted | Library – pyodata (pip) | Version(s) < 1.11.2",
      "source_url": "https://github.com/SAP/python-pyodata/security/advisories/GHSA-hc5j-q32w-c25v",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "No SAP products impacted | Library – pyodata (pip)",
      "platform": "SAP",
      "release_version": "< 1.11.2",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 5.9",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists GHSA-hc5j-q32w-c25v in its 2026-08 Security Patch Day release for No SAP products impacted | Library – pyodata (pip). The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-66773"
        ],
        "details": [
          {
            "id": "CVE-2026-66773",
            "title": "Server-controlled `__next` URL is not checking cross-origin",
            "summary": "A malicious or compromised OData service could disclose sensitive authentication information and inject untrusted data into the application, which may leads to a high impact on confidentiality and low impact on integrity and no impact on Availability.",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00194,
            "epssPercentile": 0.09193,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 5.9,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-66773",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-08-3745182",
      "slug": "sap-2026-08-3745182",
      "cycle_id": "2026-08",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3745182",
      "title": "Assess and apply SAP security advisory 3745182",
      "source_title": "[CVE-2026-58236] OS Command Injection vulnerability in Application Server ABAP of SAP NetWeaver and ABAP Platform Product - SAP NetWeaver Application Server ABAP and ABAP Platform | Version(s) - KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, KERNEL 7.22, 7.53, 7.54, 7.77, 7.93, 9.16",
      "source_url": "https://me.sap.com/notes/3745182",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "SAP NetWeaver Application Server ABAP and ABAP Platform",
      "platform": "SAP",
      "release_version": "KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, KERNEL 7.22, 7.53, 7.54, 7.77, 7.93, 9.16",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 5.5",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3745182 in its 2026-08 Security Patch Day release for SAP NetWeaver Application Server ABAP and ABAP Platform. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-58236"
        ],
        "details": [
          {
            "id": "CVE-2026-58236",
            "title": "OS Command Injection vulnerability in Application Server ABAP of SAP NetWeaver and ABAP Platform",
            "summary": "SAP NetWeaver Application Server ABAP and ABAP Platform allow an attacker with high privileges to bypass missing security controls on an internal code path leading to operating system command execution. Successful exploitation could allow the attacker to execute OS-level commands that write to the operating system or stop the SAP system, resulting in no impact on confidentiality, low impact on integrity, and high imp",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00377,
            "epssPercentile": 0.30814,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 5.5,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-58236",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-08-3540688",
      "slug": "sap-2026-08-3540688",
      "cycle_id": "2026-08",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3540688",
      "title": "Assess and apply SAP security advisory 3540688",
      "source_title": "Update to Security Note released on July 2025 Patch Day: | | [CVE-2025-42947] Code Injection vulnerability in SAP FICA ODN framework Product – SAP FICA ODN framework | Versions – SAPSCORE 132, S4CORE 102, 103, 104, 105, 106, 107, 108, FI-CA 606, 616, 617, 618",
      "source_url": "https://me.sap.com/notes/3540688",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "revised",
      "product": "SAP FICA ODN framework",
      "platform": "SAP",
      "release_version": "s – SAPSCORE 132, S4CORE 102, 103, 104, 105, 106, 107, 108, FI-CA 606, 616, 617, 618",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 5.5",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3540688 in its 2026-08 Security Patch Day release for SAP FICA ODN framework. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-42947"
        ],
        "details": [
          {
            "id": "CVE-2025-42947",
            "title": "Code Injection vulnerability in SAP FICA ODN framework",
            "summary": "SAP FICA ODN framework allows a high privileged user to inject value inside the local variable which can then be executed by the application. An attacker could thereby control the behaviour of the application causing high impact on integrity, low impact on availability and no impact on confidentiality of the application.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00294,
            "epssPercentile": 0.21681,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 5.5,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-42947",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-08-3725940",
      "slug": "sap-2026-08-3725940",
      "cycle_id": "2026-08",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3725940",
      "title": "Assess and apply SAP security advisory 3725940",
      "source_title": "[CVE-2026-40130] Memory Corruption vulnerability in SAPSPrint Service Product - SAPSPrint Service | Version(s) – SAPSPRINT 8.00, 8.10",
      "source_url": "https://me.sap.com/notes/3725940",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "SAPSPrint Service",
      "platform": "SAP",
      "release_version": "SAPSPRINT 8.00, 8.10",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 5.3",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3725940 in its 2026-08 Security Patch Day release for SAPSPrint Service. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-40130"
        ],
        "details": [
          {
            "id": "CVE-2026-40130",
            "title": "Memory Corruption vulnerability in SAPSPrint Service",
            "summary": "SAP SAPSPrint Service has memory corruption vulnerabilities in the handling of certain commands. An unauthenticated attacker could send specially crafted requests that trigger a buffer overflow in the affected component. This causes a temporary service interruption and automatic restart, resulting in low impact on availability but no impact on confidentiality and integrity.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00351,
            "epssPercentile": 0.28142,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 5.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-40130",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-08-3756674",
      "slug": "sap-2026-08-3756674",
      "cycle_id": "2026-08",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3756674",
      "title": "Assess and apply SAP security advisory 3756674",
      "source_title": "[CVE-2026-58247] Memory Corruption vulnerability in SAP ABAP Platform Product - SAP ABAP Platform | Version(s) - KRNL64UC 7.53, KERNEL 7.53, 7.54, 7.77",
      "source_url": "https://me.sap.com/notes/3756674",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "SAP ABAP Platform",
      "platform": "SAP",
      "release_version": "KRNL64UC 7.53, KERNEL 7.53, 7.54, 7.77",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 5.3",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3756674 in its 2026-08 Security Patch Day release for SAP ABAP Platform. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-58247"
        ],
        "details": [
          {
            "id": "CVE-2026-58247",
            "title": "Memory Corruption vulnerability in SAP ABAP Platform",
            "summary": "SAP ABAP Platform allows an unauthenticated user to send a specially crafted request to an internal component. This could disclose limited, non-sensitive data from previously used memory, leading to a low on confidentiality, with no impact on integrity and availability of the application.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.1177,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 5.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-58247",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-08-3778462",
      "slug": "sap-2026-08-3778462",
      "cycle_id": "2026-08",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3778462",
      "title": "Assess and apply SAP security advisory 3778462",
      "source_title": "[Multiple CVEs] Security Vulnerabilities in SAP Commerce Cloud (Search and Navigation) | | Related CVEs - CVE-2026-33871, CVE-2025-58057 Product - SAP Commerce Cloud (Search and Navigation) | Version(s) - COM_CLOUD 2211, 2211-JDK21",
      "source_url": "https://me.sap.com/notes/3778462",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "SAP Commerce Cloud (Search and Navigation)",
      "platform": "SAP",
      "release_version": "COM_CLOUD 2211, 2211-JDK21",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 4.8",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3778462 in its 2026-08 Security Patch Day release for SAP Commerce Cloud (Search and Navigation). The public bulletin links 2 CVEs; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 2,
        "ids": [
          "CVE-2025-58057",
          "CVE-2026-33871"
        ],
        "details": [
          {
            "id": "CVE-2025-58057",
            "title": "Netty's BrotliDecoder is vulnerable to DoS via zip bomb style attack",
            "summary": "Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In netty-codec-compression versions 4.1.124.Final and below, and netty-codec versions 4.2.4.Final and below, when supplied with specially crafted input, BrotliDecoder and certain other decompression decoders will allocate a large number of reachable byte buffers, which",
            "score": 6.9,
            "version": "4.0",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.00601,
            "epssPercentile": 0.46583,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Medium technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2026-33871",
            "title": "Netty HTTP/2 CONTINUATION Frame Flood DoS via Zero-Byte Frame Bypass",
            "summary": "Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Final, a remote user can trigger a Denial of Service (DoS) against a Netty HTTP/2 server by sending a flood of `CONTINUATION` frames. The server's lack of a limit on the number of `CONTINUATION` frames, combined with a bypass of existing size-based mitigations using zero-byte frames, allows an user to c",
            "score": 8.7,
            "version": "4.0",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01125,
            "epssPercentile": 0.6414,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.7,
        "max_cvss_version": "4.0",
        "max_cvss_cve": "CVE-2026-33871",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-08-3669608",
      "slug": "sap-2026-08-3669608",
      "cycle_id": "2026-08",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3669608",
      "title": "Assess and apply SAP security advisory 3669608",
      "source_title": "[CVE-2026-66764] Missing Authorization check in SAP S/4 HANA (Reprocess Bank Statement Items) Product - SAP S/4 HANA (Reprocess Bank Statement Items) | Version(s) - S4CORE 104, 105, 106, 107, 108, 109",
      "source_url": "https://me.sap.com/notes/3669608",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "SAP S/4 HANA (Reprocess Bank Statement Items)",
      "platform": "SAP",
      "release_version": "S4CORE 104, 105, 106, 107, 108, 109",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 4.3",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3669608 in its 2026-08 Security Patch Day release for SAP S/4 HANA (Reprocess Bank Statement Items). The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-66764"
        ],
        "details": [
          {
            "id": "CVE-2026-66764",
            "title": "Missing Authorization check in SAP S/4 HANA (Reprocess Bank Statement Items)",
            "summary": "Reprocess Bank Statement Items in SAP S/4HANA does not perform the necessary authorization checks for authenticated users, allowing them to use rules that have not been shared with them, resulting in privilege escalation.This vulnerability has a low impact on confidentiality, with no impact on integrity and availability of the application",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00168,
            "epssPercentile": 0.06395,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 4.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-66764",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-08-3770649",
      "slug": "sap-2026-08-3770649",
      "cycle_id": "2026-08",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3770649",
      "title": "Assess and apply SAP security advisory 3770649",
      "source_title": "[CVE-2026-66772] Missing Authorization Check in SAP BusinessObjects Business Intelligence Platform (Admin Tools) Product - SAP S/4 HANA (Reprocess Bank Statement Items), SAP BusinessObjects Business Intelligence Platform (Admin Tools) | Version(s) - S4CORE 104, 105, 106, 107, 108, 109, ENTERPRISE 430, 2025",
      "source_url": "https://me.sap.com/notes/3770649",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "SAP S/4 HANA (Reprocess Bank Statement Items), SAP BusinessObjects Business Intelligence Platform (Admin Tools)",
      "platform": "SAP",
      "release_version": "S4CORE 104, 105, 106, 107, 108, 109, ENTERPRISE 430, 2025",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 4.3",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3770649 in its 2026-08 Security Patch Day release for SAP S/4 HANA (Reprocess Bank Statement Items), SAP BusinessObjects Business Intelligence Platform (Admin Tools). The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-66772"
        ],
        "details": [
          {
            "id": "CVE-2026-66772",
            "title": "Missing Authorization Check in SAP BusinessObjects Business Intelligence Platform (Admin Tools)",
            "summary": "SAP BusinessObjects Business Intelligence Platform (Admin Tools) does not perform sufficient authorization check on certain administrative functionality. An attacker authenticated as a non-administrative user could bypass this restriction to gain limited information about affected functionality. This results in a low impact on confidentiality. There is no impact on integrity and availability.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00183,
            "epssPercentile": 0.07919,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 4.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-66772",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-08-3781137",
      "slug": "sap-2026-08-3781137",
      "cycle_id": "2026-08",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3781137",
      "title": "Assess and apply SAP security advisory 3781137",
      "source_title": "[CVE-2026-58244] Missing Authorization Check in SAP Manufacturing Integration and Intelligence (MII) Product - SAP Manufacturing Integration and Intelligence | Version(s) - XMII 15.4, 15.5",
      "source_url": "https://me.sap.com/notes/3781137",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "SAP Manufacturing Integration and Intelligence",
      "platform": "SAP",
      "release_version": "XMII 15.4, 15.5",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 4.3",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3781137 in its 2026-08 Security Patch Day release for SAP Manufacturing Integration and Intelligence. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-58244"
        ],
        "details": [
          {
            "id": "CVE-2026-58244",
            "title": "Missing Authorization Check in SAP Manufacturing Integration and Intelligence (MII)",
            "summary": "SAP Manufacturing Integration and Intelligence (MII) does not perform necessary authorization check on certain application function, allowing a low-privileged authenticated attacker to access information that should be restricted to privileged users. Successful exploitation could allow the attacker to access the users account information in the application, which could be leveraged to facilitate further attacks again",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00178,
            "epssPercentile": 0.07419,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 4.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-58244",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-08-3752864",
      "slug": "sap-2026-08-3752864",
      "cycle_id": "2026-08",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3752864",
      "title": "Assess and apply SAP security advisory 3752864",
      "source_title": "[CVE-2026-58241] Missing Authorization Check in SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard) Product - SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard | Version(s) - SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 816",
      "source_url": "https://me.sap.com/notes/3752864",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard",
      "platform": "SAP",
      "release_version": "SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 816",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 4.2",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3752864 in its 2026-08 Security Patch Day release for SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-58241"
        ],
        "details": [
          {
            "id": "CVE-2026-58241",
            "title": "Missing Authorization Check in SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard)",
            "summary": "SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard) allows a low-privileged user to modify configuration tables that control access to data objects during specific operations. These unauthorized modifications could result in processing delays and operational disruption, leading to a low impact on the integrity and availability of the application with no impact on conf",
            "score": 4.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00158,
            "epssPercentile": 0.05311,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 4.2,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-58241",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-08-3763028",
      "slug": "sap-2026-08-3763028",
      "cycle_id": "2026-08",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3763028",
      "title": "Assess and apply SAP security advisory 3763028",
      "source_title": "[CVE-2026-58245] Hard-coded Credentials in SAP Advanced Planning and Optimization (Model Mix Planning) Product - SAP Advanced Planning and Optimization (Model Mix Planning) | Version(s) - SCMAPO 713, 714, S4CORE 102, 103, 104, S4COREOP 104, 105, 106, 107, 108, 109, SCM 700, 701, 702, 712",
      "source_url": "https://me.sap.com/notes/3763028",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "SAP Advanced Planning and Optimization (Model Mix Planning)",
      "platform": "SAP",
      "release_version": "SCMAPO 713, 714, S4CORE 102, 103, 104, S4COREOP 104, 105, 106, 107, 108, 109, SCM 700, 701, 702, 712",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Low; CVSS 3.8",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3763028 in its 2026-08 Security Patch Day release for SAP Advanced Planning and Optimization (Model Mix Planning). The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-58245"
        ],
        "details": [
          {
            "id": "CVE-2026-58245",
            "title": "Hard-coded Credentials in SAP Advanced Planning and Optimization (Model Mix Planning)",
            "summary": "SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential within the source code of the application to perform authorization check to access certain functionalities in the application. An attacker with high privileges could leverage this hardcoded credential to bypass authorization and delete specific planning-related restrictions in the application. Successful exploitation could res",
            "score": 3.8,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00172,
            "epssPercentile": 0.06779,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 3.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-58245",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "sap-2026-08-3739913",
      "slug": "sap-2026-08-3739913",
      "cycle_id": "2026-08",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3739913",
      "title": "Assess and apply SAP security advisory 3739913",
      "source_title": "[CVE-2026-44762] Security Misconfiguration in SAP Data Services Management Console Product - SAP Data Services Management Console | Version(s) - SBOP_DS_MANAGEMENT_CONSOLE 4.3, 2025",
      "source_url": "https://me.sap.com/notes/3739913",
      "published_at": "2026-08-11",
      "updated_at": "2026-08-11",
      "status": "active",
      "product": "SAP Data Services Management Console",
      "platform": "SAP",
      "release_version": "SBOP_DS_MANAGEMENT_CONSOLE 4.3, 2025",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Low; CVSS 3.7",
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3739913 in its 2026-08 Security Patch Day release for SAP Data Services Management Console. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2026-44762"
        ],
        "details": [
          {
            "id": "CVE-2026-44762",
            "title": "Security Misconfiguration in SAP Data Services Management Console",
            "summary": "SAP Data Services Management Console allows an overly permissive Content Security Policy (CSP) configuration and lacks certain restrictive directives, which could enable an authenticated malicious user to leverage this weakness in combination with another vulnerability to inject and execute malicious scripts within the application's context. Successful exploitation may result in a low impact on confidentiality and in",
            "score": 3.7,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00142,
            "epssPercentile": 0.03796,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-25T19:50:39Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2026-08-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      },
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 3.7,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2026-44762",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      }
    },
    {
      "id": "adobe-apsb25-06",
      "slug": "adobe-apsb25-06",
      "cycle_id": "2025-01",
      "vendor_id": "adobe",
      "vendor_name": "Adobe",
      "source_id": "adobe-security-bulletins",
      "advisory_id": "APSB25-06",
      "title": "Update Adobe Substance3D Designer to the fixed Adobe release",
      "source_title": "APSB25-06 : Security update available for Adobe Substance3D Designer",
      "source_url": "https://helpx.adobe.com/security/products/substance3d_designer/apsb25-06.html",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Adobe Substance3D Designer",
      "platform": "All",
      "release_version": "14.1",
      "action_type": "upgrade-release",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 7.8; Adobe priority 3",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21139",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Adobe Substance3D Designer exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "Adobe published APSB25-06 on Patch Tuesday for Adobe Substance3D Designer. The bulletin links 4 CVEs and provides fixed release guidance.",
      "cves": {
        "state": "complete-for-advisory",
        "vendor_stated_count": 4,
        "ids": [
          "CVE-2025-21136",
          "CVE-2025-21137",
          "CVE-2025-21138",
          "CVE-2025-21139"
        ],
        "details": [
          {
            "id": "CVE-2025-21136",
            "title": "Substance3D - Designer | Out-of-bounds Write (CWE-787)",
            "summary": "Substance3D - Designer versions 14.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00211,
            "epssPercentile": 0.1133,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21137",
            "title": "Substance3D - Designer | Heap-based Buffer Overflow (CWE-122)",
            "summary": "Substance3D - Designer versions 14.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00257,
            "epssPercentile": 0.17243,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21138",
            "title": "Substance3D - Designer | Out-of-bounds Write (CWE-787)",
            "summary": "Substance3D - Designer versions 14.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00211,
            "epssPercentile": 0.1133,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21139",
            "title": "Substance3D - Designer | Heap-based Buffer Overflow (CWE-122)",
            "summary": "Substance3D - Designer versions 14.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00257,
            "epssPercentile": 0.17243,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update path and test the fixed release against managed plug-ins, workflows and file formats before broad deployment."
      ],
      "data_gaps": [
        "Restart requirements are not asserted unless the reviewed bulletin states them explicitly."
      ],
      "provenance": [
        {
          "field": "advisory_identity_and_release",
          "source_path": "adobe-bulletin/solution",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships",
          "source_path": "adobe-bulletin/vulnerability-details",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial publication of APSB25-06."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The bulletin identity, release date, fixed versions, platforms, vendor signals and complete public CVE list were generated from the official Adobe bulletin and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "adobe-apsb25-02",
      "slug": "adobe-apsb25-02",
      "cycle_id": "2025-01",
      "vendor_id": "adobe",
      "vendor_name": "Adobe",
      "source_id": "adobe-security-bulletins",
      "advisory_id": "APSB25-02",
      "title": "Update Adobe Photoshop to the fixed Adobe release",
      "source_title": "APSB25-02 : Security update available for Adobe Photoshop",
      "source_url": "https://helpx.adobe.com/security/products/photoshop/apsb25-02.html",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Adobe Photoshop",
      "platform": "See Adobe bulletin",
      "release_version": null,
      "action_type": "upgrade-release",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 7.8",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21127",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Adobe Photoshop exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "Adobe published APSB25-02 on Patch Tuesday for Adobe Photoshop. The bulletin links 2 CVEs and provides fixed release guidance.",
      "cves": {
        "state": "complete-for-advisory",
        "vendor_stated_count": 2,
        "ids": [
          "CVE-2025-21122",
          "CVE-2025-21127"
        ],
        "details": [
          {
            "id": "CVE-2025-21122",
            "title": "Photoshop Desktop | Integer Underflow (Wrap or Wraparound) (CWE-191)",
            "summary": "Photoshop Desktop versions 25.12, 26.1 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00274,
            "epssPercentile": 0.19523,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21127",
            "title": "Photoshop Desktop | Uncontrolled Search Path Element (CWE-427)",
            "summary": "Photoshop Desktop versions 25.12, 26.1 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could lead to arbitrary code execution. An attacker could manipulate the search path environment variable to point to a malicious library, resulting in the execution of arbitrary code when the application loads. Exploitation of this issue requires user interaction in that a victim must run the vul",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00285,
            "epssPercentile": 0.20714,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update path and test the fixed release against managed plug-ins, workflows and file formats before broad deployment."
      ],
      "data_gaps": [
        "Restart requirements are not asserted unless the reviewed bulletin states them explicitly."
      ],
      "provenance": [
        {
          "field": "advisory_identity_and_release",
          "source_path": "adobe-bulletin/solution",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships",
          "source_path": "adobe-bulletin/vulnerability-details",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial publication of APSB25-02."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The bulletin identity, release date, fixed versions, platforms, vendor signals and complete public CVE list were generated from the official Adobe bulletin and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "adobe-apsb25-03",
      "slug": "adobe-apsb25-03",
      "cycle_id": "2025-01",
      "vendor_id": "adobe",
      "vendor_name": "Adobe",
      "source_id": "adobe-security-bulletins",
      "advisory_id": "APSB25-03",
      "title": "Update Adobe Substance3D Stager to the fixed Adobe release",
      "source_title": "APSB25-03 : Security update available for Adobe Substance3D Stager",
      "source_url": "https://helpx.adobe.com/security/products/substance3d_stager/apsb25-03.html",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Adobe Substance3D Stager",
      "platform": "Windows and macOS",
      "release_version": "3.1.0",
      "action_type": "upgrade-release",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 7.8; Adobe priority 3",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21132",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Adobe Substance3D Stager exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "Adobe published APSB25-03 on Patch Tuesday for Adobe Substance3D Stager. The bulletin links 5 CVEs and provides fixed release guidance.",
      "cves": {
        "state": "complete-for-advisory",
        "vendor_stated_count": 5,
        "ids": [
          "CVE-2025-21128",
          "CVE-2025-21129",
          "CVE-2025-21130",
          "CVE-2025-21131",
          "CVE-2025-21132"
        ],
        "details": [
          {
            "id": "CVE-2025-21128",
            "title": "Substance3D - Stager | Stack-based Buffer Overflow (CWE-121)",
            "summary": "Substance3D - Stager versions 3.0.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00259,
            "epssPercentile": 0.1741,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21129",
            "title": "Substance3D - Stager | Heap-based Buffer Overflow (CWE-122)",
            "summary": "Substance3D - Stager versions 3.0.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00259,
            "epssPercentile": 0.1741,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21130",
            "title": "Substance3D - Stager | Out-of-bounds Write (CWE-787)",
            "summary": "Substance3D - Stager versions 3.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00212,
            "epssPercentile": 0.11494,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21131",
            "title": "Substance3D - Stager | Out-of-bounds Write (CWE-787)",
            "summary": "Substance3D - Stager versions 3.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00212,
            "epssPercentile": 0.11495,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21132",
            "title": "Substance3D - Stager | Out-of-bounds Write (CWE-787)",
            "summary": "Substance3D - Stager versions 3.0.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00212,
            "epssPercentile": 0.11495,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update path and test the fixed release against managed plug-ins, workflows and file formats before broad deployment."
      ],
      "data_gaps": [
        "Restart requirements are not asserted unless the reviewed bulletin states them explicitly."
      ],
      "provenance": [
        {
          "field": "advisory_identity_and_release",
          "source_path": "adobe-bulletin/solution",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships",
          "source_path": "adobe-bulletin/vulnerability-details",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial publication of APSB25-03."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The bulletin identity, release date, fixed versions, platforms, vendor signals and complete public CVE list were generated from the official Adobe bulletin and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "adobe-apsb25-05",
      "slug": "adobe-apsb25-05",
      "cycle_id": "2025-01",
      "vendor_id": "adobe",
      "vendor_name": "Adobe",
      "source_id": "adobe-security-bulletins",
      "advisory_id": "APSB25-05",
      "title": "Update Adobe Animate to the fixed Adobe release",
      "source_title": "APSB25-05 : Security update available for Adobe Animate",
      "source_url": "https://helpx.adobe.com/security/products/animate/apsb25-05.html",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Adobe Animate",
      "platform": "Windows and macOS",
      "release_version": "23.0.10, 24.0.7",
      "action_type": "upgrade-release",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 7.8; Adobe priority 3",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21135",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Adobe Animate exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "Adobe published APSB25-05 on Patch Tuesday for Adobe Animate. The bulletin links 1 CVE and provides fixed release guidance.",
      "cves": {
        "state": "complete-for-advisory",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21135"
        ],
        "details": [
          {
            "id": "CVE-2025-21135",
            "title": "Animate | Integer Underflow (Wrap or Wraparound) (CWE-191)",
            "summary": "Animate versions 24.0.6, 23.0.9 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00274,
            "epssPercentile": 0.19523,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update path and test the fixed release against managed plug-ins, workflows and file formats before broad deployment."
      ],
      "data_gaps": [
        "Restart requirements are not asserted unless the reviewed bulletin states them explicitly."
      ],
      "provenance": [
        {
          "field": "advisory_identity_and_release",
          "source_path": "adobe-bulletin/solution",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships",
          "source_path": "adobe-bulletin/vulnerability-details",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial publication of APSB25-05."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The bulletin identity, release date, fixed versions, platforms, vendor signals and complete public CVE list were generated from the official Adobe bulletin and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "adobe-apsb25-04",
      "slug": "adobe-apsb25-04",
      "cycle_id": "2025-01",
      "vendor_id": "adobe",
      "vendor_name": "Adobe",
      "source_id": "adobe-security-bulletins",
      "advisory_id": "APSB25-04",
      "title": "Update Adobe Illustrator for iPad to the fixed Adobe release",
      "source_title": "APSB25-04 : Security update available for Adobe Illustrator for iPad",
      "source_url": "https://helpx.adobe.com/security/products/illustrator-mobile-ios/apsb25-04.html",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Adobe Illustrator for iPad",
      "platform": "iOS",
      "release_version": "3.0.8",
      "action_type": "upgrade-release",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 7.8; Adobe priority 3",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21134",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Adobe Illustrator for iPad exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "Adobe published APSB25-04 on Patch Tuesday for Adobe Illustrator for iPad. The bulletin links 2 CVEs and provides fixed release guidance.",
      "cves": {
        "state": "complete-for-advisory",
        "vendor_stated_count": 2,
        "ids": [
          "CVE-2025-21133",
          "CVE-2025-21134"
        ],
        "details": [
          {
            "id": "CVE-2025-21133",
            "title": "Illustrator on iPad | Integer Underflow (Wrap or Wraparound) (CWE-191)",
            "summary": "Illustrator on iPad versions 3.0.7 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00251,
            "epssPercentile": 0.16401,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21134",
            "title": "Illustrator on iPad | Integer Underflow (Wrap or Wraparound) (CWE-191)",
            "summary": "Illustrator on iPad versions 3.0.7 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00251,
            "epssPercentile": 0.16401,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update path and test the fixed release against managed plug-ins, workflows and file formats before broad deployment."
      ],
      "data_gaps": [
        "Restart requirements are not asserted unless the reviewed bulletin states them explicitly."
      ],
      "provenance": [
        {
          "field": "advisory_identity_and_release",
          "source_path": "adobe-bulletin/solution",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships",
          "source_path": "adobe-bulletin/vulnerability-details",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial publication of APSB25-04."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The bulletin identity, release date, fixed versions, platforms, vendor signals and complete public CVE list were generated from the official Adobe bulletin and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-azure-msrc-2025-01-azure-release-notes-on-premises-data-gateway",
      "slug": "microsoft-2025-01-azure-msrc-2025-01-azure-release-notes-on-premises-data-gateway",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-01-azure-release-notes",
      "title": "Deploy Microsoft Azure update for On-Premises Data Gateway",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://download.microsoft.com/download/D/A/1/DA1FDDB8-6DA8-4F50-B4D0-18019591E182/GatewayInstall.exe",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "On-Premises Data Gateway",
      "platform": "Azure",
      "release_version": "3000.246",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 6.4,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21403",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is On-Premises Data Gateway exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for On-Premises Data Gateway.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21403"
        ],
        "details": [
          {
            "id": "CVE-2025-21403",
            "title": "On-Premises Data Gateway Information Disclosure Vulnerability",
            "summary": "On-Premises Data Gateway Information Disclosure Vulnerability",
            "score": 6.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00604,
            "epssPercentile": 0.46702,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-browser-msrc-2025-01-browser-release-notes-microsoft-edge-chromium-based",
      "slug": "microsoft-2025-01-browser-msrc-2025-01-browser-release-notes-microsoft-edge-chromium-based",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-01-browser-release-notes",
      "title": "Deploy Microsoft Browser update for Microsoft Edge (Chromium-based)",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://msrc.microsoft.com/update-guide/releaseNote/2025-Jan",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft Edge (Chromium-based)",
      "platform": "Browser",
      "release_version": "131.0.2903.147",
      "action_type": "deploy-patch",
      "restart_required": "no",
      "vendor_severity": null,
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-0291",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "The reviewed source does not require a restart.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Edge (Chromium-based) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Edge (Chromium-based).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-0291"
        ],
        "details": [
          {
            "id": "CVE-2025-0291",
            "title": "Type Confusion in V8 in Google Chrome prior to 131.0.6778.264 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page",
            "summary": "Type Confusion in V8 in Google Chrome prior to 131.0.6778.264 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "NIST NVD",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.07935,
            "epssPercentile": 0.94345,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-developer-tools-kb5049614",
      "slug": "microsoft-2025-01-developer-tools-kb5049614",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5049614",
      "title": "Deploy Microsoft Developer Tools security update KB5049614",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5049614",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 4.8 on Windows Server 2016, plus 1 more",
      "platform": "Developer Tools",
      "release_version": "4.8.04775.01",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21176",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 4.8 on Windows Server 2016, plus 1 more exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 4.8 on Windows Server 2016, plus 1 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21176"
        ],
        "details": [
          {
            "id": "CVE-2025-21176",
            "title": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "summary": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02347,
            "epssPercentile": 0.82555,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-developer-tools-kb5049620",
      "slug": "microsoft-2025-01-developer-tools-kb5049620",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5049620",
      "title": "Deploy Microsoft Developer Tools security update KB5049620",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5049620",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2022, 23H2 Edition (Server Core installation)",
      "platform": "Developer Tools",
      "release_version": "4.8.1.09294.01",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21176",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2022, 23H2 Edition (Server Core installation) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2022, 23H2 Edition (Server Core installation).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21176"
        ],
        "details": [
          {
            "id": "CVE-2025-21176",
            "title": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "summary": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02347,
            "epssPercentile": 0.82555,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-developer-tools-kb5049622",
      "slug": "microsoft-2025-01-developer-tools-kb5049622",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5049622",
      "title": "Deploy Microsoft Developer Tools security update KB5049622",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5049622",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 24H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 24H2 for x64-based Systems",
      "platform": "Developer Tools",
      "release_version": "4.8.1.09294.01",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21176",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 24H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 24H2 for x64-based Systems exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 24H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 24H2 for x64-based Systems.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21176"
        ],
        "details": [
          {
            "id": "CVE-2025-21176",
            "title": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "summary": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02347,
            "epssPercentile": 0.82555,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-developer-tools-kb5049624",
      "slug": "microsoft-2025-01-developer-tools-kb5049624",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5049624",
      "title": "Deploy Microsoft Developer Tools security update KB5049624",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5049624",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 22H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 22H2 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 23H2 for ARM64-based Systems, plus 1 more",
      "platform": "Developer Tools",
      "release_version": "4.8.1.09294.01",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21176",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 22H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 22H2 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 23H2 for ARM64-based Systems, plus 1 more exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 22H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 22H2 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 23H2 for ARM64-based Systems, plus 1 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21176"
        ],
        "details": [
          {
            "id": "CVE-2025-21176",
            "title": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "summary": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02347,
            "epssPercentile": 0.82555,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-developer-tools-kb5049688",
      "slug": "microsoft-2025-01-developer-tools-kb5049688",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5049688",
      "title": "Deploy Microsoft Developer Tools security update KB5049688",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5049688",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft Visual Studio 2015 Update 3",
      "platform": "Developer Tools",
      "release_version": "14.0.24252.2",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21178",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Visual Studio 2015 Update 3 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft Visual Studio 2015 Update 3.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 3,
        "ids": [
          "CVE-2025-21172",
          "CVE-2025-21176",
          "CVE-2025-21178"
        ],
        "details": [
          {
            "id": "CVE-2025-21172",
            "title": ".NET and Visual Studio Remote Code Execution Vulnerability",
            "summary": ".NET and Visual Studio Remote Code Execution Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01815,
            "epssPercentile": 0.77247,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21176",
            "title": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "summary": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02347,
            "epssPercentile": 0.82555,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21178",
            "title": "Visual Studio Remote Code Execution Vulnerability",
            "summary": "Visual Studio Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01581,
            "epssPercentile": 0.73889,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-developer-tools-kb5049993",
      "slug": "microsoft-2025-01-developer-tools-kb5049993",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5049993",
      "title": "Deploy Microsoft Developer Tools security update KB5049993",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5049993",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2016, plus 1 more",
      "platform": "Developer Tools",
      "release_version": "10.0.14393.7699",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21176",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2016, plus 1 more exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2016, plus 1 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21176"
        ],
        "details": [
          {
            "id": "CVE-2025-21176",
            "title": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "summary": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02347,
            "epssPercentile": 0.82555,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-developer-tools-kb5050013",
      "slug": "microsoft-2025-01-developer-tools-kb5050013",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5050013",
      "title": "Deploy Microsoft Developer Tools security update KB5050013",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5050013",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft .NET Framework 4.6/4.6.2 on Windows 10 for 32-bit Systems, Microsoft .NET Framework 4.6/4.6.2 on Windows 10 for x64-based Systems",
      "platform": "Developer Tools",
      "release_version": "10.0.10240.20890",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21176",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft .NET Framework 4.6/4.6.2 on Windows 10 for 32-bit Systems, Microsoft .NET Framework 4.6/4.6.2 on Windows 10 for x64-based Systems exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft .NET Framework 4.6/4.6.2 on Windows 10 for 32-bit Systems, Microsoft .NET Framework 4.6/4.6.2 on Windows 10 for x64-based Systems.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21176"
        ],
        "details": [
          {
            "id": "CVE-2025-21176",
            "title": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "summary": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02347,
            "epssPercentile": 0.82555,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-developer-tools-kb5050180",
      "slug": "microsoft-2025-01-developer-tools-kb5050180",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5050180",
      "title": "Deploy Microsoft Developer Tools security update KB5050180",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5050180",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation), Microsoft .NET Framework 4.8 on Windows Server 2008 R2 for x64-based Systems Service Pack 1, plus 1 more",
      "platform": "Developer Tools",
      "release_version": "4.7.04126.02, 4.8.04775.02",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21176",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation), Microsoft .NET Framework 4.8 on Windows Server 2008 R2 for x64-based Systems Service Pack 1, plus 1 more exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation), Microsoft .NET Framework 4.8 on Windows Server 2008 R2 for x64-based Systems Service Pack 1, plus 1 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21176"
        ],
        "details": [
          {
            "id": "CVE-2025-21176",
            "title": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "summary": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02347,
            "epssPercentile": 0.82555,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-developer-tools-kb5050181",
      "slug": "microsoft-2025-01-developer-tools-kb5050181",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5050181",
      "title": "Deploy Microsoft Developer Tools security update KB5050181",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5050181",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft .NET Framework 4.6.2 on Windows Server 2008 for 32-bit Systems Service Pack 2, Microsoft .NET Framework 4.6.2 on Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Microsoft .NET Framework 4.6.2 on Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more",
      "platform": "Developer Tools",
      "release_version": "4.7.04126.02",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21176",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft .NET Framework 4.6.2 on Windows Server 2008 for 32-bit Systems Service Pack 2, Microsoft .NET Framework 4.6.2 on Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Microsoft .NET Framework 4.6.2 on Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft .NET Framework 4.6.2 on Windows Server 2008 for 32-bit Systems Service Pack 2, Microsoft .NET Framework 4.6.2 on Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Microsoft .NET Framework 4.6.2 on Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21176"
        ],
        "details": [
          {
            "id": "CVE-2025-21176",
            "title": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "summary": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02347,
            "epssPercentile": 0.82555,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-developer-tools-kb5050182",
      "slug": "microsoft-2025-01-developer-tools-kb5050182",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5050182",
      "title": "Deploy Microsoft Developer Tools security update KB5050182",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5050182",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2019, plus 5 more",
      "platform": "Developer Tools",
      "release_version": "4.7.04126.01, 4.8.04775.01",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21176",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2019, plus 5 more exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2019, plus 5 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21176"
        ],
        "details": [
          {
            "id": "CVE-2025-21176",
            "title": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "summary": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02347,
            "epssPercentile": 0.82555,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-developer-tools-kb5050183",
      "slug": "microsoft-2025-01-developer-tools-kb5050183",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5050183",
      "title": "Deploy Microsoft Developer Tools security update KB5050183",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5050183",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation), Microsoft .NET Framework 4.8 on Windows Server 2008 R2 for x64-based Systems Service Pack 1, plus 1 more",
      "platform": "Developer Tools",
      "release_version": "4.7.04126.01, 4.8.04775.01",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21176",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation), Microsoft .NET Framework 4.8 on Windows Server 2008 R2 for x64-based Systems Service Pack 1, plus 1 more exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation), Microsoft .NET Framework 4.8 on Windows Server 2008 R2 for x64-based Systems Service Pack 1, plus 1 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21176"
        ],
        "details": [
          {
            "id": "CVE-2025-21176",
            "title": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "summary": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02347,
            "epssPercentile": 0.82555,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-developer-tools-kb5050184",
      "slug": "microsoft-2025-01-developer-tools-kb5050184",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5050184",
      "title": "Deploy Microsoft Developer Tools security update KB5050184",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5050184",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 (Server Core installation), Microsoft .NET Framework 4.8 on Windows Server 2012, plus 1 more",
      "platform": "Developer Tools",
      "release_version": "4.7.04126.01, 4.8.04775.01",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21176",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 (Server Core installation), Microsoft .NET Framework 4.8 on Windows Server 2012, plus 1 more exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 (Server Core installation), Microsoft .NET Framework 4.8 on Windows Server 2012, plus 1 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21176"
        ],
        "details": [
          {
            "id": "CVE-2025-21176",
            "title": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "summary": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02347,
            "epssPercentile": 0.82555,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-developer-tools-kb5050185",
      "slug": "microsoft-2025-01-developer-tools-kb5050185",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5050185",
      "title": "Deploy Microsoft Developer Tools security update KB5050185",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5050185",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2 (Server Core installation), Microsoft .NET Framework 4.8 on Windows Server 2012 R2, plus 1 more",
      "platform": "Developer Tools",
      "release_version": "4.7.04126.01, 4.8.04775.01",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21176",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2 (Server Core installation), Microsoft .NET Framework 4.8 on Windows Server 2012 R2, plus 1 more exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2 (Server Core installation), Microsoft .NET Framework 4.8 on Windows Server 2012 R2, plus 1 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21176"
        ],
        "details": [
          {
            "id": "CVE-2025-21176",
            "title": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "summary": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02347,
            "epssPercentile": 0.82555,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-developer-tools-kb5050186",
      "slug": "microsoft-2025-01-developer-tools-kb5050186",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5050186",
      "title": "Deploy Microsoft Developer Tools security update KB5050186",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5050186",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft .NET Framework 4.6.2 on Windows Server 2008 for 32-bit Systems Service Pack 2, Microsoft .NET Framework 4.6.2 on Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Microsoft .NET Framework 4.6.2 on Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more",
      "platform": "Developer Tools",
      "release_version": "4.7.04126.01",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21176",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft .NET Framework 4.6.2 on Windows Server 2008 for 32-bit Systems Service Pack 2, Microsoft .NET Framework 4.6.2 on Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Microsoft .NET Framework 4.6.2 on Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft .NET Framework 4.6.2 on Windows Server 2008 for 32-bit Systems Service Pack 2, Microsoft .NET Framework 4.6.2 on Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Microsoft .NET Framework 4.6.2 on Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21176"
        ],
        "details": [
          {
            "id": "CVE-2025-21176",
            "title": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "summary": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02347,
            "epssPercentile": 0.82555,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-developer-tools-kb5050187",
      "slug": "microsoft-2025-01-developer-tools-kb5050187",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5050187",
      "title": "Deploy Microsoft Developer Tools security update KB5050187",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5050187",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022, Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022 (Server Core installation), Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2022, plus 1 more",
      "platform": "Developer Tools",
      "release_version": "4.8.04775.01, 4.8.1.09294.01",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21176",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022, Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022 (Server Core installation), Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2022, plus 1 more exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022, Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022 (Server Core installation), Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2022, plus 1 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21176"
        ],
        "details": [
          {
            "id": "CVE-2025-21176",
            "title": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "summary": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02347,
            "epssPercentile": 0.82555,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-developer-tools-kb5050188",
      "slug": "microsoft-2025-01-developer-tools-kb5050188",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5050188",
      "title": "Deploy Microsoft Developer Tools security update KB5050188",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5050188",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for x64-based Systems, plus 3 more",
      "platform": "Developer Tools",
      "release_version": "4.8.04775.01, 4.8.1.09294.01",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21176",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for x64-based Systems, plus 3 more exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for x64-based Systems, plus 3 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21176"
        ],
        "details": [
          {
            "id": "CVE-2025-21176",
            "title": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "summary": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02347,
            "epssPercentile": 0.82555,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-developer-tools-kb5050416",
      "slug": "microsoft-2025-01-developer-tools-kb5050416",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5050416",
      "title": "Deploy Microsoft Developer Tools security update KB5050416",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5050416",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for x64-based Systems, plus 3 more",
      "platform": "Developer Tools",
      "release_version": "4.8.04775.01, 4.8.1.09294.01",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21176",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for x64-based Systems, plus 3 more exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for x64-based Systems, plus 3 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21176"
        ],
        "details": [
          {
            "id": "CVE-2025-21176",
            "title": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "summary": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02347,
            "epssPercentile": 0.82555,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-developer-tools-kb5050525",
      "slug": "microsoft-2025-01-developer-tools-kb5050525",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5050525",
      "title": "Deploy Microsoft Developer Tools security update KB5050525",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5050525",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": ".NET 8.0 installed on Linux, .NET 8.0 installed on Mac OS, .NET 8.0 installed on Windows",
      "platform": "Developer Tools",
      "release_version": "8.0.12",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21176",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is .NET 8.0 installed on Linux, .NET 8.0 installed on Mac OS, .NET 8.0 installed on Windows exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 3 linked CVEs for .NET 8.0 installed on Linux, .NET 8.0 installed on Mac OS, .NET 8.0 installed on Windows.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 3,
        "ids": [
          "CVE-2025-21172",
          "CVE-2025-21173",
          "CVE-2025-21176"
        ],
        "details": [
          {
            "id": "CVE-2025-21172",
            "title": ".NET and Visual Studio Remote Code Execution Vulnerability",
            "summary": ".NET and Visual Studio Remote Code Execution Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01815,
            "epssPercentile": 0.77247,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21173",
            "title": ".NET Elevation of Privilege Vulnerability",
            "summary": ".NET Elevation of Privilege Vulnerability",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01243,
            "epssPercentile": 0.67259,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21176",
            "title": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "summary": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02347,
            "epssPercentile": 0.82555,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-developer-tools-kb5050526",
      "slug": "microsoft-2025-01-developer-tools-kb5050526",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5050526",
      "title": "Deploy Microsoft Developer Tools security update KB5050526",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5050526",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": ".NET 9.0 installed on Linux, .NET 9.0 installed on Mac OS, .NET 9.0 installed on Windows",
      "platform": "Developer Tools",
      "release_version": "9.0.1",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21176",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is .NET 9.0 installed on Linux, .NET 9.0 installed on Mac OS, .NET 9.0 installed on Windows exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 4 linked CVEs for .NET 9.0 installed on Linux, .NET 9.0 installed on Mac OS, .NET 9.0 installed on Windows.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 4,
        "ids": [
          "CVE-2025-21171",
          "CVE-2025-21172",
          "CVE-2025-21173",
          "CVE-2025-21176"
        ],
        "details": [
          {
            "id": "CVE-2025-21171",
            "title": ".NET Remote Code Execution Vulnerability",
            "summary": ".NET Remote Code Execution Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01698,
            "epssPercentile": 0.75655,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21172",
            "title": ".NET and Visual Studio Remote Code Execution Vulnerability",
            "summary": ".NET and Visual Studio Remote Code Execution Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01815,
            "epssPercentile": 0.77247,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21173",
            "title": ".NET Elevation of Privilege Vulnerability",
            "summary": ".NET Elevation of Privilege Vulnerability",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01243,
            "epssPercentile": 0.67259,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21176",
            "title": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "summary": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02347,
            "epssPercentile": 0.82555,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-developer-tools-msrc-2025-01-developer-tools-release-notes-powershell-7-5-installed-on-windows",
      "slug": "microsoft-2025-01-developer-tools-msrc-2025-01-developer-tools-release-notes-powershell-7-5-installed-on-windows",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-01-developer-tools-release-notes",
      "title": "Deploy Microsoft Developer Tools update for PowerShell 7.5 installed on Windows",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://github.com/PowerShell/Announcements/issues/72",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "PowerShell 7.5 installed on Windows",
      "platform": "Developer Tools",
      "release_version": "7.5.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.5,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21171",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is PowerShell 7.5 installed on Windows exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for PowerShell 7.5 installed on Windows.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21171"
        ],
        "details": [
          {
            "id": "CVE-2025-21171",
            "title": ".NET Remote Code Execution Vulnerability",
            "summary": ".NET Remote Code Execution Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01698,
            "epssPercentile": 0.75655,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-developer-tools-msrc-2025-01-developer-tools-release-notes-powershell-7-5-installed-on-linux",
      "slug": "microsoft-2025-01-developer-tools-msrc-2025-01-developer-tools-release-notes-powershell-7-5-installed-on-linux",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-01-developer-tools-release-notes",
      "title": "Deploy Microsoft Developer Tools update for PowerShell 7.5 installed on Linux",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://github.com/PowerShell/Announcements/issues/72",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "PowerShell 7.5 installed on Linux",
      "platform": "Developer Tools",
      "release_version": "7.5.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.5,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21171",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is PowerShell 7.5 installed on Linux exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for PowerShell 7.5 installed on Linux.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21171"
        ],
        "details": [
          {
            "id": "CVE-2025-21171",
            "title": ".NET Remote Code Execution Vulnerability",
            "summary": ".NET Remote Code Execution Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01698,
            "epssPercentile": 0.75655,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-developer-tools-msrc-2025-01-developer-tools-release-notes-powershell-7-5-installed-on-macos",
      "slug": "microsoft-2025-01-developer-tools-msrc-2025-01-developer-tools-release-notes-powershell-7-5-installed-on-macos",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-01-developer-tools-release-notes",
      "title": "Deploy Microsoft Developer Tools update for PowerShell 7.5 installed on MacOS",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://github.com/PowerShell/Announcements/issues/72",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "PowerShell 7.5 installed on MacOS",
      "platform": "Developer Tools",
      "release_version": "7.5.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.5,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21171",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is PowerShell 7.5 installed on MacOS exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for PowerShell 7.5 installed on MacOS.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21171"
        ],
        "details": [
          {
            "id": "CVE-2025-21171",
            "title": ".NET Remote Code Execution Vulnerability",
            "summary": ".NET Remote Code Execution Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01698,
            "epssPercentile": 0.75655,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-developer-tools-msrc-2025-01-developer-tools-release-notes-microsoft-visual-studio-2022-version-17-12",
      "slug": "microsoft-2025-01-developer-tools-msrc-2025-01-developer-tools-release-notes-microsoft-visual-studio-2022-version-17-12",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-01-developer-tools-release-notes",
      "title": "Deploy Microsoft Developer Tools update for Microsoft Visual Studio 2022 version 17.12",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.12",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft Visual Studio 2022 version 17.12",
      "platform": "Developer Tools",
      "release_version": "17.12.4",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21178",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Visual Studio 2022 version 17.12 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 6 linked CVEs for Microsoft Visual Studio 2022 version 17.12.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 6,
        "ids": [
          "CVE-2025-21171",
          "CVE-2025-21172",
          "CVE-2025-21173",
          "CVE-2025-21176",
          "CVE-2025-21178",
          "CVE-2025-21405"
        ],
        "details": [
          {
            "id": "CVE-2025-21171",
            "title": ".NET Remote Code Execution Vulnerability",
            "summary": ".NET Remote Code Execution Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01698,
            "epssPercentile": 0.75655,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21172",
            "title": ".NET and Visual Studio Remote Code Execution Vulnerability",
            "summary": ".NET and Visual Studio Remote Code Execution Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01815,
            "epssPercentile": 0.77247,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21173",
            "title": ".NET Elevation of Privilege Vulnerability",
            "summary": ".NET Elevation of Privilege Vulnerability",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01243,
            "epssPercentile": 0.67259,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21176",
            "title": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "summary": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02347,
            "epssPercentile": 0.82555,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21178",
            "title": "Visual Studio Remote Code Execution Vulnerability",
            "summary": "Visual Studio Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01581,
            "epssPercentile": 0.73889,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21405",
            "title": "Visual Studio Elevation of Privilege Vulnerability",
            "summary": "Visual Studio Elevation of Privilege Vulnerability",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00523,
            "epssPercentile": 0.42463,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-developer-tools-msrc-2025-01-developer-tools-release-notes-microsoft-visual-studio-2022-version-17-6",
      "slug": "microsoft-2025-01-developer-tools-msrc-2025-01-developer-tools-release-notes-microsoft-visual-studio-2022-version-17-6",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-01-developer-tools-release-notes",
      "title": "Deploy Microsoft Developer Tools update for Microsoft Visual Studio 2022 version 17.6",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.6",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft Visual Studio 2022 version 17.6",
      "platform": "Developer Tools",
      "release_version": "17.6.22",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21178",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Visual Studio 2022 version 17.6 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 5 linked CVEs for Microsoft Visual Studio 2022 version 17.6.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 5,
        "ids": [
          "CVE-2025-21171",
          "CVE-2025-21172",
          "CVE-2025-21173",
          "CVE-2025-21176",
          "CVE-2025-21178"
        ],
        "details": [
          {
            "id": "CVE-2025-21171",
            "title": ".NET Remote Code Execution Vulnerability",
            "summary": ".NET Remote Code Execution Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01698,
            "epssPercentile": 0.75655,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21172",
            "title": ".NET and Visual Studio Remote Code Execution Vulnerability",
            "summary": ".NET and Visual Studio Remote Code Execution Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01815,
            "epssPercentile": 0.77247,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21173",
            "title": ".NET Elevation of Privilege Vulnerability",
            "summary": ".NET Elevation of Privilege Vulnerability",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01243,
            "epssPercentile": 0.67259,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21176",
            "title": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "summary": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02347,
            "epssPercentile": 0.82555,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21178",
            "title": "Visual Studio Remote Code Execution Vulnerability",
            "summary": "Visual Studio Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01581,
            "epssPercentile": 0.73889,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-developer-tools-msrc-2025-01-developer-tools-release-notes-microsoft-visual-studio-2022-version-17-8",
      "slug": "microsoft-2025-01-developer-tools-msrc-2025-01-developer-tools-release-notes-microsoft-visual-studio-2022-version-17-8",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-01-developer-tools-release-notes",
      "title": "Deploy Microsoft Developer Tools update for Microsoft Visual Studio 2022 version 17.8",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.8",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft Visual Studio 2022 version 17.8",
      "platform": "Developer Tools",
      "release_version": "17.8.17",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21178",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Visual Studio 2022 version 17.8 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 5 linked CVEs for Microsoft Visual Studio 2022 version 17.8.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 5,
        "ids": [
          "CVE-2025-21171",
          "CVE-2025-21172",
          "CVE-2025-21173",
          "CVE-2025-21176",
          "CVE-2025-21178"
        ],
        "details": [
          {
            "id": "CVE-2025-21171",
            "title": ".NET Remote Code Execution Vulnerability",
            "summary": ".NET Remote Code Execution Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01698,
            "epssPercentile": 0.75655,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21172",
            "title": ".NET and Visual Studio Remote Code Execution Vulnerability",
            "summary": ".NET and Visual Studio Remote Code Execution Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01815,
            "epssPercentile": 0.77247,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21173",
            "title": ".NET Elevation of Privilege Vulnerability",
            "summary": ".NET Elevation of Privilege Vulnerability",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01243,
            "epssPercentile": 0.67259,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21176",
            "title": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "summary": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02347,
            "epssPercentile": 0.82555,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21178",
            "title": "Visual Studio Remote Code Execution Vulnerability",
            "summary": "Visual Studio Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01581,
            "epssPercentile": 0.73889,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-developer-tools-msrc-2025-01-developer-tools-release-notes-microsoft-visual-studio-2022-version-17-10",
      "slug": "microsoft-2025-01-developer-tools-msrc-2025-01-developer-tools-release-notes-microsoft-visual-studio-2022-version-17-10",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-01-developer-tools-release-notes",
      "title": "Deploy Microsoft Developer Tools update for Microsoft Visual Studio 2022 version 17.10",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.10",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft Visual Studio 2022 version 17.10",
      "platform": "Developer Tools",
      "release_version": "17.10.10",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21178",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Visual Studio 2022 version 17.10 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 5 linked CVEs for Microsoft Visual Studio 2022 version 17.10.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 5,
        "ids": [
          "CVE-2025-21171",
          "CVE-2025-21172",
          "CVE-2025-21173",
          "CVE-2025-21176",
          "CVE-2025-21178"
        ],
        "details": [
          {
            "id": "CVE-2025-21171",
            "title": ".NET Remote Code Execution Vulnerability",
            "summary": ".NET Remote Code Execution Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01698,
            "epssPercentile": 0.75655,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21172",
            "title": ".NET and Visual Studio Remote Code Execution Vulnerability",
            "summary": ".NET and Visual Studio Remote Code Execution Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01815,
            "epssPercentile": 0.77247,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21173",
            "title": ".NET Elevation of Privilege Vulnerability",
            "summary": ".NET Elevation of Privilege Vulnerability",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01243,
            "epssPercentile": 0.67259,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21176",
            "title": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "summary": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02347,
            "epssPercentile": 0.82555,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21178",
            "title": "Visual Studio Remote Code Execution Vulnerability",
            "summary": "Visual Studio Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01581,
            "epssPercentile": 0.73889,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-developer-tools-msrc-2025-01-developer-tools-release-notes-microsoft-visual-studio-2017-version-15-9-includes-15-0-15-8",
      "slug": "microsoft-2025-01-developer-tools-msrc-2025-01-developer-tools-release-notes-microsoft-visual-studio-2017-version-15-9-includes-15-0-15-8",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-01-developer-tools-release-notes",
      "title": "Deploy Microsoft Developer Tools update for Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://aka.ms/vs/15/release/latest",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)",
      "platform": "Developer Tools",
      "release_version": "15.9.69",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21178",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 3,
        "ids": [
          "CVE-2025-21172",
          "CVE-2025-21176",
          "CVE-2025-21178"
        ],
        "details": [
          {
            "id": "CVE-2025-21172",
            "title": ".NET and Visual Studio Remote Code Execution Vulnerability",
            "summary": ".NET and Visual Studio Remote Code Execution Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01815,
            "epssPercentile": 0.77247,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21176",
            "title": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "summary": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02347,
            "epssPercentile": 0.82555,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21178",
            "title": "Visual Studio Remote Code Execution Vulnerability",
            "summary": "Visual Studio Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01581,
            "epssPercentile": 0.73889,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-developer-tools-msrc-2025-01-developer-tools-release-notes-microsoft-visual-studio-2019-version-16-11-includes-16-0-16-10",
      "slug": "microsoft-2025-01-developer-tools-msrc-2025-01-developer-tools-release-notes-microsoft-visual-studio-2019-version-16-11-includes-16-0-16-10",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-01-developer-tools-release-notes",
      "title": "Deploy Microsoft Developer Tools update for Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://my.visualstudio.com/Downloads?q=Visual Studio 2019 version 16.11",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)",
      "platform": "Developer Tools",
      "release_version": "16.11.43",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21178",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 3,
        "ids": [
          "CVE-2025-21172",
          "CVE-2025-21176",
          "CVE-2025-21178"
        ],
        "details": [
          {
            "id": "CVE-2025-21172",
            "title": ".NET and Visual Studio Remote Code Execution Vulnerability",
            "summary": ".NET and Visual Studio Remote Code Execution Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01815,
            "epssPercentile": 0.77247,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21176",
            "title": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "summary": ".NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02347,
            "epssPercentile": 0.82555,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21178",
            "title": "Visual Studio Remote Code Execution Vulnerability",
            "summary": "Visual Studio Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01581,
            "epssPercentile": 0.73889,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-esu-kb5049981",
      "slug": "microsoft-2025-01-esu-kb5049981",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5049981",
      "title": "Deploy Microsoft ESU security update KB5049981",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5049981",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Windows 10 Version 22H2 for 32-bit Systems, Windows 10 Version 22H2 for ARM64-based Systems, Windows 10 Version 22H2 for x64-based Systems",
      "platform": "ESU",
      "release_version": "10.0.19045.5371",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21307",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows 10 Version 22H2 for 32-bit Systems, Windows 10 Version 22H2 for ARM64-based Systems, Windows 10 Version 22H2 for x64-based Systems exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 119 linked CVEs for Windows 10 Version 22H2 for 32-bit Systems, Windows 10 Version 22H2 for ARM64-based Systems, Windows 10 Version 22H2 for x64-based Systems. Microsoft reports exploitation for CVE-2025-21333, CVE-2025-21334, CVE-2025-21335.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 119,
        "ids": [
          "CVE-2025-21189",
          "CVE-2025-21202",
          "CVE-2025-21207",
          "CVE-2025-21210",
          "CVE-2025-21211",
          "CVE-2025-21213",
          "CVE-2025-21214",
          "CVE-2025-21215",
          "CVE-2025-21217",
          "CVE-2025-21219",
          "CVE-2025-21220",
          "CVE-2025-21223",
          "CVE-2025-21224",
          "CVE-2025-21226",
          "CVE-2025-21227",
          "CVE-2025-21228",
          "CVE-2025-21229",
          "CVE-2025-21230",
          "CVE-2025-21231",
          "CVE-2025-21232",
          "CVE-2025-21233",
          "CVE-2025-21234",
          "CVE-2025-21235",
          "CVE-2025-21236",
          "CVE-2025-21237",
          "CVE-2025-21238",
          "CVE-2025-21239",
          "CVE-2025-21240",
          "CVE-2025-21241",
          "CVE-2025-21242",
          "CVE-2025-21243",
          "CVE-2025-21244",
          "CVE-2025-21245",
          "CVE-2025-21246",
          "CVE-2025-21248",
          "CVE-2025-21249",
          "CVE-2025-21250",
          "CVE-2025-21251",
          "CVE-2025-21252",
          "CVE-2025-21255",
          "CVE-2025-21256",
          "CVE-2025-21257",
          "CVE-2025-21258",
          "CVE-2025-21260",
          "CVE-2025-21261",
          "CVE-2025-21263",
          "CVE-2025-21265",
          "CVE-2025-21266",
          "CVE-2025-21268",
          "CVE-2025-21269",
          "CVE-2025-21270",
          "CVE-2025-21271",
          "CVE-2025-21272",
          "CVE-2025-21273",
          "CVE-2025-21274",
          "CVE-2025-21275",
          "CVE-2025-21276",
          "CVE-2025-21277",
          "CVE-2025-21278",
          "CVE-2025-21280",
          "CVE-2025-21281",
          "CVE-2025-21282",
          "CVE-2025-21284",
          "CVE-2025-21285",
          "CVE-2025-21286",
          "CVE-2025-21287",
          "CVE-2025-21288",
          "CVE-2025-21289",
          "CVE-2025-21290",
          "CVE-2025-21291",
          "CVE-2025-21292",
          "CVE-2025-21293",
          "CVE-2025-21294",
          "CVE-2025-21295",
          "CVE-2025-21296",
          "CVE-2025-21298",
          "CVE-2025-21299",
          "CVE-2025-21300",
          "CVE-2025-21301",
          "CVE-2025-21302",
          "CVE-2025-21303",
          "CVE-2025-21304",
          "CVE-2025-21305",
          "CVE-2025-21306",
          "CVE-2025-21307",
          "CVE-2025-21308",
          "CVE-2025-21310",
          "CVE-2025-21312",
          "CVE-2025-21314",
          "CVE-2025-21316",
          "CVE-2025-21317",
          "CVE-2025-21318",
          "CVE-2025-21319",
          "CVE-2025-21320",
          "CVE-2025-21321",
          "CVE-2025-21323",
          "CVE-2025-21324",
          "CVE-2025-21327",
          "CVE-2025-21328",
          "CVE-2025-21329",
          "CVE-2025-21330",
          "CVE-2025-21331",
          "CVE-2025-21332",
          "CVE-2025-21333",
          "CVE-2025-21334",
          "CVE-2025-21335",
          "CVE-2025-21336",
          "CVE-2025-21338",
          "CVE-2025-21339",
          "CVE-2025-21340",
          "CVE-2025-21341",
          "CVE-2025-21374",
          "CVE-2025-21378",
          "CVE-2025-21382",
          "CVE-2025-21389",
          "CVE-2025-21409",
          "CVE-2025-21411",
          "CVE-2025-21413",
          "CVE-2025-21417"
        ],
        "details": [
          {
            "id": "CVE-2025-21189",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02971,
            "epssPercentile": 0.86348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21202",
            "title": "Windows Recovery Environment Agent Elevation of Privilege Vulnerability",
            "summary": "Windows Recovery Environment Agent Elevation of Privilege Vulnerability",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0088,
            "epssPercentile": 0.56753,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21207",
            "title": "Windows Connected Devices Platform Service (Cdpsvc) Denial of Service Vulnerability",
            "summary": "Windows Connected Devices Platform Service (Cdpsvc) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02108,
            "epssPercentile": 0.80554,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21210",
            "title": "Windows BitLocker Information Disclosure Vulnerability",
            "summary": "Windows BitLocker Information Disclosure Vulnerability",
            "score": 4.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01139,
            "epssPercentile": 0.64494,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21211",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Secure Boot Security Feature Bypass Vulnerability",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00773,
            "epssPercentile": 0.53349,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21213",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Secure Boot Security Feature Bypass Vulnerability",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0072,
            "epssPercentile": 0.51578,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21214",
            "title": "Windows BitLocker Information Disclosure Vulnerability",
            "summary": "Windows BitLocker Information Disclosure Vulnerability",
            "score": 4.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00713,
            "epssPercentile": 0.51333,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21215",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Secure Boot Security Feature Bypass Vulnerability",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00818,
            "epssPercentile": 0.5483,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21217",
            "title": "Windows NTLM Spoofing Vulnerability",
            "summary": "Windows NTLM Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01948,
            "epssPercentile": 0.78877,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21219",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03017,
            "epssPercentile": 0.86549,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21220",
            "title": "Microsoft Message Queuing Information Disclosure Vulnerability",
            "summary": "Microsoft Message Queuing Information Disclosure Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02151,
            "epssPercentile": 0.80943,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21223",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01621,
            "epssPercentile": 0.74499,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21224",
            "title": "Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability",
            "summary": "Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01908,
            "epssPercentile": 0.78413,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21226",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00867,
            "epssPercentile": 0.5638,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21227",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21228",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21229",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21230",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02686,
            "epssPercentile": 0.84872,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21231",
            "title": "IP Helper Denial of Service Vulnerability",
            "summary": "IP Helper Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02591,
            "epssPercentile": 0.84283,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21232",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21233",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21234",
            "title": "Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability",
            "summary": "Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00598,
            "epssPercentile": 0.46439,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21235",
            "title": "Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability",
            "summary": "Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00596,
            "epssPercentile": 0.46331,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21236",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21237",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21238",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21239",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01489,
            "epssPercentile": 0.7238,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21240",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21241",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01489,
            "epssPercentile": 0.7238,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21242",
            "title": "Windows Kerberos Information Disclosure Vulnerability",
            "summary": "Windows Kerberos Information Disclosure Vulnerability",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01646,
            "epssPercentile": 0.74883,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21243",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21244",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21245",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21246",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21248",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01489,
            "epssPercentile": 0.72379,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21249",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21250",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21251",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02591,
            "epssPercentile": 0.84283,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21252",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21255",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21256",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21257",
            "title": "Windows WLAN AutoConfig Service Information Disclosure Vulnerability",
            "summary": "Windows WLAN AutoConfig Service Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00732,
            "epssPercentile": 0.51998,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21258",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21260",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55328,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21261",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21263",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21265",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21266",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21268",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01989,
            "epssPercentile": 0.79308,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21269",
            "title": "Windows HTML Platforms Security Feature Bypass Vulnerability",
            "summary": "Windows HTML Platforms Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.04593,
            "epssPercentile": 0.91034,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21270",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21271",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0054,
            "epssPercentile": 0.43498,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21272",
            "title": "Windows COM Server Information Disclosure Vulnerability",
            "summary": "Windows COM Server Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00706,
            "epssPercentile": 0.51085,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21273",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21274",
            "title": "Windows Event Tracing Denial of Service Vulnerability",
            "summary": "Windows Event Tracing Denial of Service Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00785,
            "epssPercentile": 0.53739,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21275",
            "title": "Windows App Package Installer Elevation of Privilege Vulnerability",
            "summary": "Windows App Package Installer Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00618,
            "epssPercentile": 0.47369,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21276",
            "title": "Windows MapUrlToZone Denial of Service Vulnerability",
            "summary": "Windows MapUrlToZone Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02421,
            "epssPercentile": 0.83098,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21277",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.38612,
            "epssPercentile": 0.98478,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21278",
            "title": "Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability",
            "summary": "Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0057,
            "epssPercentile": 0.45061,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21280",
            "title": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability",
            "summary": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49634,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21281",
            "title": "Microsoft COM for Windows Elevation of Privilege Vulnerability",
            "summary": "Microsoft COM for Windows Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00605,
            "epssPercentile": 0.46774,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21282",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21284",
            "title": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability",
            "summary": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49634,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21285",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.55686,
            "epssPercentile": 0.9897,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21286",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21287",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00549,
            "epssPercentile": 0.43984,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21288",
            "title": "Windows COM Server Information Disclosure Vulnerability",
            "summary": "Windows COM Server Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00706,
            "epssPercentile": 0.51085,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21289",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21290",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21291",
            "title": "Windows Direct Show Remote Code Execution Vulnerability",
            "summary": "Windows Direct Show Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01396,
            "epssPercentile": 0.70616,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21292",
            "title": "Windows Search Service Elevation of Privilege Vulnerability",
            "summary": "Windows Search Service Elevation of Privilege Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00825,
            "epssPercentile": 0.55027,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21293",
            "title": "Active Directory Domain Services Elevation of Privilege Vulnerability",
            "summary": "Active Directory Domain Services Elevation of Privilege Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.18825,
            "epssPercentile": 0.97091,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21294",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01209,
            "epssPercentile": 0.66385,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21295",
            "title": "SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability",
            "summary": "SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0161,
            "epssPercentile": 0.74316,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21296",
            "title": "BranchCache Remote Code Execution Vulnerability",
            "summary": "BranchCache Remote Code Execution Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00778,
            "epssPercentile": 0.53536,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21298",
            "title": "Windows OLE Remote Code Execution Vulnerability",
            "summary": "Windows OLE Remote Code Execution Vulnerability",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "CISA Vulnrichment records proof-of-concept exploitation in its SSVC data. BlackTree has not independently executed or validated exploit material.",
            "epss": 0.80912,
            "epssPercentile": 0.99602,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path and a public exploit reference; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21299",
            "title": "Windows Kerberos Security Feature Bypass Vulnerability",
            "summary": "Windows Kerberos Security Feature Bypass Vulnerability",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02212,
            "epssPercentile": 0.81462,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21300",
            "title": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "summary": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02531,
            "epssPercentile": 0.83874,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21301",
            "title": "Windows Geolocation Service Information Disclosure Vulnerability",
            "summary": "Windows Geolocation Service Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01564,
            "epssPercentile": 0.73648,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21302",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21303",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21304",
            "title": "Microsoft DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Microsoft DWM Core Library Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00604,
            "epssPercentile": 0.46711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21305",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21306",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70986,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21307",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01909,
            "epssPercentile": 0.7842,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21308",
            "title": "Windows Themes Spoofing Vulnerability",
            "summary": "Windows Themes Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02208,
            "epssPercentile": 0.81432,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21310",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21312",
            "title": "Windows Smart Card Reader Information Disclosure Vulnerability",
            "summary": "Windows Smart Card Reader Information Disclosure Vulnerability",
            "score": 2.4,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00718,
            "epssPercentile": 0.51518,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21314",
            "title": "Windows SmartScreen Spoofing Vulnerability",
            "summary": "Windows SmartScreen Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01421,
            "epssPercentile": 0.71094,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21316",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58304,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21317",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0085,
            "epssPercentile": 0.55808,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21318",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21319",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21320",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21321",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21323",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0085,
            "epssPercentile": 0.55807,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21324",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21327",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21328",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01518,
            "epssPercentile": 0.72882,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21329",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01518,
            "epssPercentile": 0.72882,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21330",
            "title": "Windows Remote Desktop Services Denial of Service Vulnerability",
            "summary": "Windows Remote Desktop Services Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01961,
            "epssPercentile": 0.79002,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21331",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01019,
            "epssPercentile": 0.61089,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21332",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01474,
            "epssPercentile": 0.72107,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21333",
            "title": "Microsoft Windows Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows Hyper-V NT Kernel Integration VSP contains a heap-based buffer overflow vulnerability that allows a local attacker to gain SYSTEM privileges.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-01-14.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.09988,
            "epssPercentile": 0.95287,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-02-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21334",
            "title": "Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability",
            "summary": "Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-01-14.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01561,
            "epssPercentile": 0.73599,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-02-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21335",
            "title": "Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability",
            "summary": "Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-01-14.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0139,
            "epssPercentile": 0.70518,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-02-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21336",
            "title": "Windows Cryptographic Information Disclosure Vulnerability",
            "summary": "Windows Cryptographic Information Disclosure Vulnerability",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00631,
            "epssPercentile": 0.47982,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21338",
            "title": "GDI+ Remote Code Execution Vulnerability",
            "summary": "GDI+ Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39683,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21339",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21340",
            "title": "Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability",
            "summary": "Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00452,
            "epssPercentile": 0.37841,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21341",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00698,
            "epssPercentile": 0.50753,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21374",
            "title": "Windows CSC Service Information Disclosure Vulnerability",
            "summary": "Windows CSC Service Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00587,
            "epssPercentile": 0.45949,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21378",
            "title": "Windows CSC Service Elevation of Privilege Vulnerability",
            "summary": "Windows CSC Service Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00564,
            "epssPercentile": 0.4479,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21382",
            "title": "Windows Graphics Component Elevation of Privilege Vulnerability",
            "summary": "Windows Graphics Component Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00503,
            "epssPercentile": 0.41206,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21389",
            "title": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "summary": "Uncontrolled resource consumption in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0194,
            "epssPercentile": 0.78785,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21409",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21411",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21413",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21417",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01171,
            "epssPercentile": 0.6537,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-esu-kb5049994",
      "slug": "microsoft-2025-01-esu-kb5049994",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5049994",
      "title": "Deploy Microsoft ESU security update KB5049994",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5049994",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation), Windows Server 2008 for 32-bit Systems Service Pack 2, plus 7 more",
      "platform": "ESU",
      "release_version": "1.002, 1.003, 1.007",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.5,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21276",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation), Windows Server 2008 for 32-bit Systems Service Pack 2, plus 7 more exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 7 linked CVEs for Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation), Windows Server 2008 for 32-bit Systems Service Pack 2, plus 7 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 7,
        "ids": [
          "CVE-2025-21189",
          "CVE-2025-21268",
          "CVE-2025-21269",
          "CVE-2025-21276",
          "CVE-2025-21328",
          "CVE-2025-21329",
          "CVE-2025-21332"
        ],
        "details": [
          {
            "id": "CVE-2025-21189",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02971,
            "epssPercentile": 0.86348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21268",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01989,
            "epssPercentile": 0.79308,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21269",
            "title": "Windows HTML Platforms Security Feature Bypass Vulnerability",
            "summary": "Windows HTML Platforms Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.04593,
            "epssPercentile": 0.91034,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21276",
            "title": "Windows MapUrlToZone Denial of Service Vulnerability",
            "summary": "Windows MapUrlToZone Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02421,
            "epssPercentile": 0.83098,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21328",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01518,
            "epssPercentile": 0.72882,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21329",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01518,
            "epssPercentile": 0.72882,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21332",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01474,
            "epssPercentile": 0.72107,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-esu-kb5050004",
      "slug": "microsoft-2025-01-esu-kb5050004",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5050004",
      "title": "Deploy Microsoft ESU security update KB5050004",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5050004",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Windows Server 2012, Windows Server 2012 (Server Core installation)",
      "platform": "ESU",
      "release_version": "6.2.9200.25273",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21307",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows Server 2012, Windows Server 2012 (Server Core installation) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 92 linked CVEs for Windows Server 2012, Windows Server 2012 (Server Core installation). Microsoft marks CVE-2025-21308 as publicly disclosed, without that disclosure alone changing the BlackTree action window.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 92,
        "ids": [
          "CVE-2025-21189",
          "CVE-2025-21210",
          "CVE-2025-21211",
          "CVE-2025-21213",
          "CVE-2025-21214",
          "CVE-2025-21215",
          "CVE-2025-21217",
          "CVE-2025-21218",
          "CVE-2025-21220",
          "CVE-2025-21223",
          "CVE-2025-21226",
          "CVE-2025-21227",
          "CVE-2025-21228",
          "CVE-2025-21229",
          "CVE-2025-21230",
          "CVE-2025-21231",
          "CVE-2025-21232",
          "CVE-2025-21233",
          "CVE-2025-21236",
          "CVE-2025-21237",
          "CVE-2025-21238",
          "CVE-2025-21240",
          "CVE-2025-21242",
          "CVE-2025-21243",
          "CVE-2025-21244",
          "CVE-2025-21245",
          "CVE-2025-21246",
          "CVE-2025-21249",
          "CVE-2025-21250",
          "CVE-2025-21251",
          "CVE-2025-21252",
          "CVE-2025-21255",
          "CVE-2025-21256",
          "CVE-2025-21258",
          "CVE-2025-21260",
          "CVE-2025-21261",
          "CVE-2025-21263",
          "CVE-2025-21265",
          "CVE-2025-21266",
          "CVE-2025-21268",
          "CVE-2025-21269",
          "CVE-2025-21270",
          "CVE-2025-21272",
          "CVE-2025-21273",
          "CVE-2025-21276",
          "CVE-2025-21277",
          "CVE-2025-21278",
          "CVE-2025-21281",
          "CVE-2025-21282",
          "CVE-2025-21285",
          "CVE-2025-21286",
          "CVE-2025-21287",
          "CVE-2025-21288",
          "CVE-2025-21289",
          "CVE-2025-21290",
          "CVE-2025-21293",
          "CVE-2025-21294",
          "CVE-2025-21295",
          "CVE-2025-21296",
          "CVE-2025-21297",
          "CVE-2025-21298",
          "CVE-2025-21300",
          "CVE-2025-21302",
          "CVE-2025-21303",
          "CVE-2025-21305",
          "CVE-2025-21306",
          "CVE-2025-21307",
          "CVE-2025-21308",
          "CVE-2025-21309",
          "CVE-2025-21310",
          "CVE-2025-21312",
          "CVE-2025-21318",
          "CVE-2025-21319",
          "CVE-2025-21320",
          "CVE-2025-21321",
          "CVE-2025-21324",
          "CVE-2025-21327",
          "CVE-2025-21328",
          "CVE-2025-21329",
          "CVE-2025-21331",
          "CVE-2025-21332",
          "CVE-2025-21336",
          "CVE-2025-21338",
          "CVE-2025-21339",
          "CVE-2025-21341",
          "CVE-2025-21374",
          "CVE-2025-21378",
          "CVE-2025-21389",
          "CVE-2025-21409",
          "CVE-2025-21411",
          "CVE-2025-21413",
          "CVE-2025-21417"
        ],
        "details": [
          {
            "id": "CVE-2025-21189",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02971,
            "epssPercentile": 0.86348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21210",
            "title": "Windows BitLocker Information Disclosure Vulnerability",
            "summary": "Windows BitLocker Information Disclosure Vulnerability",
            "score": 4.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01139,
            "epssPercentile": 0.64494,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21211",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Secure Boot Security Feature Bypass Vulnerability",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00773,
            "epssPercentile": 0.53349,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21213",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Secure Boot Security Feature Bypass Vulnerability",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0072,
            "epssPercentile": 0.51578,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21214",
            "title": "Windows BitLocker Information Disclosure Vulnerability",
            "summary": "Windows BitLocker Information Disclosure Vulnerability",
            "score": 4.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00713,
            "epssPercentile": 0.51333,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21215",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Secure Boot Security Feature Bypass Vulnerability",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00818,
            "epssPercentile": 0.5483,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21217",
            "title": "Windows NTLM Spoofing Vulnerability",
            "summary": "Windows NTLM Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01948,
            "epssPercentile": 0.78877,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21218",
            "title": "Windows Kerberos Denial of Service Vulnerability",
            "summary": "Windows Kerberos Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02589,
            "epssPercentile": 0.8425,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21220",
            "title": "Microsoft Message Queuing Information Disclosure Vulnerability",
            "summary": "Microsoft Message Queuing Information Disclosure Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02151,
            "epssPercentile": 0.80943,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21223",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01621,
            "epssPercentile": 0.74499,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21226",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00867,
            "epssPercentile": 0.5638,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21227",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21228",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21229",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21230",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02686,
            "epssPercentile": 0.84872,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21231",
            "title": "IP Helper Denial of Service Vulnerability",
            "summary": "IP Helper Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02591,
            "epssPercentile": 0.84283,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21232",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21233",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21236",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21237",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21238",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21240",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21242",
            "title": "Windows Kerberos Information Disclosure Vulnerability",
            "summary": "Windows Kerberos Information Disclosure Vulnerability",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01646,
            "epssPercentile": 0.74883,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21243",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21244",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21245",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21246",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21249",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21250",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21251",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02591,
            "epssPercentile": 0.84283,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21252",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21255",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21256",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21258",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21260",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55328,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21261",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21263",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21265",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21266",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21268",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01989,
            "epssPercentile": 0.79308,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21269",
            "title": "Windows HTML Platforms Security Feature Bypass Vulnerability",
            "summary": "Windows HTML Platforms Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.04593,
            "epssPercentile": 0.91034,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21270",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21272",
            "title": "Windows COM Server Information Disclosure Vulnerability",
            "summary": "Windows COM Server Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00706,
            "epssPercentile": 0.51085,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21273",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21276",
            "title": "Windows MapUrlToZone Denial of Service Vulnerability",
            "summary": "Windows MapUrlToZone Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02421,
            "epssPercentile": 0.83098,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21277",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.38612,
            "epssPercentile": 0.98478,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21278",
            "title": "Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability",
            "summary": "Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0057,
            "epssPercentile": 0.45061,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21281",
            "title": "Microsoft COM for Windows Elevation of Privilege Vulnerability",
            "summary": "Microsoft COM for Windows Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00605,
            "epssPercentile": 0.46774,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21282",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21285",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.55686,
            "epssPercentile": 0.9897,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21286",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21287",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00549,
            "epssPercentile": 0.43984,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21288",
            "title": "Windows COM Server Information Disclosure Vulnerability",
            "summary": "Windows COM Server Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00706,
            "epssPercentile": 0.51085,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21289",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21290",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21293",
            "title": "Active Directory Domain Services Elevation of Privilege Vulnerability",
            "summary": "Active Directory Domain Services Elevation of Privilege Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.18825,
            "epssPercentile": 0.97091,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21294",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01209,
            "epssPercentile": 0.66385,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21295",
            "title": "SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability",
            "summary": "SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0161,
            "epssPercentile": 0.74316,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21296",
            "title": "BranchCache Remote Code Execution Vulnerability",
            "summary": "BranchCache Remote Code Execution Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00778,
            "epssPercentile": 0.53536,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21297",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01436,
            "epssPercentile": 0.71362,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21298",
            "title": "Windows OLE Remote Code Execution Vulnerability",
            "summary": "Windows OLE Remote Code Execution Vulnerability",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "CISA Vulnrichment records proof-of-concept exploitation in its SSVC data. BlackTree has not independently executed or validated exploit material.",
            "epss": 0.80912,
            "epssPercentile": 0.99602,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path and a public exploit reference; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21300",
            "title": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "summary": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02531,
            "epssPercentile": 0.83874,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21302",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21303",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21305",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21306",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70986,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21307",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01909,
            "epssPercentile": 0.7842,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21308",
            "title": "Windows Themes Spoofing Vulnerability",
            "summary": "Windows Themes Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02208,
            "epssPercentile": 0.81432,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21309",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.14979,
            "epssPercentile": 0.96482,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21310",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21312",
            "title": "Windows Smart Card Reader Information Disclosure Vulnerability",
            "summary": "Windows Smart Card Reader Information Disclosure Vulnerability",
            "score": 2.4,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00718,
            "epssPercentile": 0.51518,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21318",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21319",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21320",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21321",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21324",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21327",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21328",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01518,
            "epssPercentile": 0.72882,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21329",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01518,
            "epssPercentile": 0.72882,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21331",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01019,
            "epssPercentile": 0.61089,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21332",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01474,
            "epssPercentile": 0.72107,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21336",
            "title": "Windows Cryptographic Information Disclosure Vulnerability",
            "summary": "Windows Cryptographic Information Disclosure Vulnerability",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00631,
            "epssPercentile": 0.47982,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21338",
            "title": "GDI+ Remote Code Execution Vulnerability",
            "summary": "GDI+ Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39683,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21339",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21341",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00698,
            "epssPercentile": 0.50753,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21374",
            "title": "Windows CSC Service Information Disclosure Vulnerability",
            "summary": "Windows CSC Service Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00587,
            "epssPercentile": 0.45949,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21378",
            "title": "Windows CSC Service Elevation of Privilege Vulnerability",
            "summary": "Windows CSC Service Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00564,
            "epssPercentile": 0.4479,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21389",
            "title": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "summary": "Uncontrolled resource consumption in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0194,
            "epssPercentile": 0.78785,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21409",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21411",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21413",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21417",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01171,
            "epssPercentile": 0.6537,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-esu-kb5050006",
      "slug": "microsoft-2025-01-esu-kb5050006",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5050006",
      "title": "Deploy Microsoft ESU security update KB5050006",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5050006",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)",
      "platform": "ESU",
      "release_version": "6.1.7601.27520",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21307",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 71 linked CVEs for Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 71,
        "ids": [
          "CVE-2025-21210",
          "CVE-2025-21214",
          "CVE-2025-21215",
          "CVE-2025-21217",
          "CVE-2025-21220",
          "CVE-2025-21223",
          "CVE-2025-21226",
          "CVE-2025-21227",
          "CVE-2025-21228",
          "CVE-2025-21230",
          "CVE-2025-21231",
          "CVE-2025-21232",
          "CVE-2025-21233",
          "CVE-2025-21236",
          "CVE-2025-21237",
          "CVE-2025-21238",
          "CVE-2025-21240",
          "CVE-2025-21242",
          "CVE-2025-21243",
          "CVE-2025-21244",
          "CVE-2025-21245",
          "CVE-2025-21246",
          "CVE-2025-21249",
          "CVE-2025-21250",
          "CVE-2025-21251",
          "CVE-2025-21252",
          "CVE-2025-21255",
          "CVE-2025-21256",
          "CVE-2025-21258",
          "CVE-2025-21260",
          "CVE-2025-21261",
          "CVE-2025-21263",
          "CVE-2025-21265",
          "CVE-2025-21266",
          "CVE-2025-21270",
          "CVE-2025-21272",
          "CVE-2025-21273",
          "CVE-2025-21277",
          "CVE-2025-21282",
          "CVE-2025-21285",
          "CVE-2025-21286",
          "CVE-2025-21287",
          "CVE-2025-21288",
          "CVE-2025-21289",
          "CVE-2025-21290",
          "CVE-2025-21294",
          "CVE-2025-21295",
          "CVE-2025-21296",
          "CVE-2025-21297",
          "CVE-2025-21298",
          "CVE-2025-21300",
          "CVE-2025-21302",
          "CVE-2025-21303",
          "CVE-2025-21305",
          "CVE-2025-21306",
          "CVE-2025-21307",
          "CVE-2025-21310",
          "CVE-2025-21319",
          "CVE-2025-21320",
          "CVE-2025-21324",
          "CVE-2025-21327",
          "CVE-2025-21331",
          "CVE-2025-21336",
          "CVE-2025-21338",
          "CVE-2025-21339",
          "CVE-2025-21341",
          "CVE-2025-21389",
          "CVE-2025-21409",
          "CVE-2025-21411",
          "CVE-2025-21413",
          "CVE-2025-21417"
        ],
        "details": [
          {
            "id": "CVE-2025-21210",
            "title": "Windows BitLocker Information Disclosure Vulnerability",
            "summary": "Windows BitLocker Information Disclosure Vulnerability",
            "score": 4.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01139,
            "epssPercentile": 0.64494,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21214",
            "title": "Windows BitLocker Information Disclosure Vulnerability",
            "summary": "Windows BitLocker Information Disclosure Vulnerability",
            "score": 4.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00713,
            "epssPercentile": 0.51333,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21215",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Secure Boot Security Feature Bypass Vulnerability",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00818,
            "epssPercentile": 0.5483,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21217",
            "title": "Windows NTLM Spoofing Vulnerability",
            "summary": "Windows NTLM Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01948,
            "epssPercentile": 0.78877,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21220",
            "title": "Microsoft Message Queuing Information Disclosure Vulnerability",
            "summary": "Microsoft Message Queuing Information Disclosure Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02151,
            "epssPercentile": 0.80943,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21223",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01621,
            "epssPercentile": 0.74499,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21226",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00867,
            "epssPercentile": 0.5638,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21227",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21228",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21230",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02686,
            "epssPercentile": 0.84872,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21231",
            "title": "IP Helper Denial of Service Vulnerability",
            "summary": "IP Helper Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02591,
            "epssPercentile": 0.84283,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21232",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21233",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21236",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21237",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21238",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21240",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21242",
            "title": "Windows Kerberos Information Disclosure Vulnerability",
            "summary": "Windows Kerberos Information Disclosure Vulnerability",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01646,
            "epssPercentile": 0.74883,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21243",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21244",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21245",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21246",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21249",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21250",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21251",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02591,
            "epssPercentile": 0.84283,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21252",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21255",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21256",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21258",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21260",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55328,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21261",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21263",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21265",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21266",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21270",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21272",
            "title": "Windows COM Server Information Disclosure Vulnerability",
            "summary": "Windows COM Server Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00706,
            "epssPercentile": 0.51085,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21273",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21277",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.38612,
            "epssPercentile": 0.98478,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21282",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21285",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.55686,
            "epssPercentile": 0.9897,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21286",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21287",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00549,
            "epssPercentile": 0.43984,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21288",
            "title": "Windows COM Server Information Disclosure Vulnerability",
            "summary": "Windows COM Server Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00706,
            "epssPercentile": 0.51085,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21289",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21290",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21294",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01209,
            "epssPercentile": 0.66385,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21295",
            "title": "SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability",
            "summary": "SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0161,
            "epssPercentile": 0.74316,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21296",
            "title": "BranchCache Remote Code Execution Vulnerability",
            "summary": "BranchCache Remote Code Execution Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00778,
            "epssPercentile": 0.53536,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21297",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01436,
            "epssPercentile": 0.71362,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21298",
            "title": "Windows OLE Remote Code Execution Vulnerability",
            "summary": "Windows OLE Remote Code Execution Vulnerability",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "CISA Vulnrichment records proof-of-concept exploitation in its SSVC data. BlackTree has not independently executed or validated exploit material.",
            "epss": 0.80912,
            "epssPercentile": 0.99602,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path and a public exploit reference; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21300",
            "title": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "summary": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02531,
            "epssPercentile": 0.83874,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21302",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21303",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21305",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21306",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70986,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21307",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01909,
            "epssPercentile": 0.7842,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21310",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21319",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21320",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21324",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21327",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21331",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01019,
            "epssPercentile": 0.61089,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21336",
            "title": "Windows Cryptographic Information Disclosure Vulnerability",
            "summary": "Windows Cryptographic Information Disclosure Vulnerability",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00631,
            "epssPercentile": 0.47982,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21338",
            "title": "GDI+ Remote Code Execution Vulnerability",
            "summary": "GDI+ Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39683,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21339",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21341",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00698,
            "epssPercentile": 0.50753,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21389",
            "title": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "summary": "Uncontrolled resource consumption in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0194,
            "epssPercentile": 0.78785,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21409",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21411",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21413",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21417",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01171,
            "epssPercentile": 0.6537,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-esu-kb5050021",
      "slug": "microsoft-2025-01-esu-kb5050021",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5050021",
      "title": "Deploy Microsoft ESU security update KB5050021",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5050021",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Windows 11 Version 22H2 for ARM64-based Systems, Windows 11 Version 22H2 for x64-based Systems",
      "platform": "ESU",
      "release_version": "10.0.22621.4751",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21307",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows 11 Version 22H2 for ARM64-based Systems, Windows 11 Version 22H2 for x64-based Systems exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 119 linked CVEs for Windows 11 Version 22H2 for ARM64-based Systems, Windows 11 Version 22H2 for x64-based Systems. Microsoft reports exploitation for CVE-2025-21333, CVE-2025-21334, CVE-2025-21335.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 119,
        "ids": [
          "CVE-2025-21189",
          "CVE-2025-21202",
          "CVE-2025-21207",
          "CVE-2025-21210",
          "CVE-2025-21211",
          "CVE-2025-21213",
          "CVE-2025-21214",
          "CVE-2025-21215",
          "CVE-2025-21217",
          "CVE-2025-21219",
          "CVE-2025-21220",
          "CVE-2025-21223",
          "CVE-2025-21224",
          "CVE-2025-21226",
          "CVE-2025-21227",
          "CVE-2025-21228",
          "CVE-2025-21229",
          "CVE-2025-21230",
          "CVE-2025-21231",
          "CVE-2025-21232",
          "CVE-2025-21233",
          "CVE-2025-21234",
          "CVE-2025-21235",
          "CVE-2025-21236",
          "CVE-2025-21237",
          "CVE-2025-21238",
          "CVE-2025-21239",
          "CVE-2025-21240",
          "CVE-2025-21241",
          "CVE-2025-21242",
          "CVE-2025-21243",
          "CVE-2025-21244",
          "CVE-2025-21245",
          "CVE-2025-21246",
          "CVE-2025-21248",
          "CVE-2025-21249",
          "CVE-2025-21250",
          "CVE-2025-21251",
          "CVE-2025-21252",
          "CVE-2025-21255",
          "CVE-2025-21256",
          "CVE-2025-21257",
          "CVE-2025-21258",
          "CVE-2025-21260",
          "CVE-2025-21261",
          "CVE-2025-21263",
          "CVE-2025-21265",
          "CVE-2025-21266",
          "CVE-2025-21268",
          "CVE-2025-21269",
          "CVE-2025-21270",
          "CVE-2025-21272",
          "CVE-2025-21273",
          "CVE-2025-21274",
          "CVE-2025-21275",
          "CVE-2025-21276",
          "CVE-2025-21277",
          "CVE-2025-21278",
          "CVE-2025-21280",
          "CVE-2025-21281",
          "CVE-2025-21282",
          "CVE-2025-21284",
          "CVE-2025-21285",
          "CVE-2025-21286",
          "CVE-2025-21287",
          "CVE-2025-21288",
          "CVE-2025-21289",
          "CVE-2025-21290",
          "CVE-2025-21291",
          "CVE-2025-21292",
          "CVE-2025-21293",
          "CVE-2025-21294",
          "CVE-2025-21295",
          "CVE-2025-21296",
          "CVE-2025-21298",
          "CVE-2025-21299",
          "CVE-2025-21300",
          "CVE-2025-21301",
          "CVE-2025-21302",
          "CVE-2025-21303",
          "CVE-2025-21305",
          "CVE-2025-21306",
          "CVE-2025-21307",
          "CVE-2025-21308",
          "CVE-2025-21310",
          "CVE-2025-21312",
          "CVE-2025-21314",
          "CVE-2025-21316",
          "CVE-2025-21317",
          "CVE-2025-21318",
          "CVE-2025-21319",
          "CVE-2025-21320",
          "CVE-2025-21321",
          "CVE-2025-21323",
          "CVE-2025-21324",
          "CVE-2025-21327",
          "CVE-2025-21328",
          "CVE-2025-21329",
          "CVE-2025-21330",
          "CVE-2025-21331",
          "CVE-2025-21332",
          "CVE-2025-21333",
          "CVE-2025-21334",
          "CVE-2025-21335",
          "CVE-2025-21336",
          "CVE-2025-21338",
          "CVE-2025-21339",
          "CVE-2025-21340",
          "CVE-2025-21341",
          "CVE-2025-21343",
          "CVE-2025-21370",
          "CVE-2025-21374",
          "CVE-2025-21378",
          "CVE-2025-21382",
          "CVE-2025-21389",
          "CVE-2025-21409",
          "CVE-2025-21411",
          "CVE-2025-21413",
          "CVE-2025-21417"
        ],
        "details": [
          {
            "id": "CVE-2025-21189",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02971,
            "epssPercentile": 0.86348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21202",
            "title": "Windows Recovery Environment Agent Elevation of Privilege Vulnerability",
            "summary": "Windows Recovery Environment Agent Elevation of Privilege Vulnerability",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0088,
            "epssPercentile": 0.56753,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21207",
            "title": "Windows Connected Devices Platform Service (Cdpsvc) Denial of Service Vulnerability",
            "summary": "Windows Connected Devices Platform Service (Cdpsvc) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02108,
            "epssPercentile": 0.80554,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21210",
            "title": "Windows BitLocker Information Disclosure Vulnerability",
            "summary": "Windows BitLocker Information Disclosure Vulnerability",
            "score": 4.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01139,
            "epssPercentile": 0.64494,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21211",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Secure Boot Security Feature Bypass Vulnerability",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00773,
            "epssPercentile": 0.53349,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21213",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Secure Boot Security Feature Bypass Vulnerability",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0072,
            "epssPercentile": 0.51578,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21214",
            "title": "Windows BitLocker Information Disclosure Vulnerability",
            "summary": "Windows BitLocker Information Disclosure Vulnerability",
            "score": 4.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00713,
            "epssPercentile": 0.51333,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21215",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Secure Boot Security Feature Bypass Vulnerability",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00818,
            "epssPercentile": 0.5483,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21217",
            "title": "Windows NTLM Spoofing Vulnerability",
            "summary": "Windows NTLM Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01948,
            "epssPercentile": 0.78877,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21219",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03017,
            "epssPercentile": 0.86549,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21220",
            "title": "Microsoft Message Queuing Information Disclosure Vulnerability",
            "summary": "Microsoft Message Queuing Information Disclosure Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02151,
            "epssPercentile": 0.80943,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21223",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01621,
            "epssPercentile": 0.74499,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21224",
            "title": "Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability",
            "summary": "Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01908,
            "epssPercentile": 0.78413,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21226",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00867,
            "epssPercentile": 0.5638,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21227",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21228",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21229",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21230",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02686,
            "epssPercentile": 0.84872,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21231",
            "title": "IP Helper Denial of Service Vulnerability",
            "summary": "IP Helper Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02591,
            "epssPercentile": 0.84283,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21232",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21233",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21234",
            "title": "Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability",
            "summary": "Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00598,
            "epssPercentile": 0.46439,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21235",
            "title": "Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability",
            "summary": "Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00596,
            "epssPercentile": 0.46331,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21236",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21237",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21238",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21239",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01489,
            "epssPercentile": 0.7238,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21240",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21241",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01489,
            "epssPercentile": 0.7238,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21242",
            "title": "Windows Kerberos Information Disclosure Vulnerability",
            "summary": "Windows Kerberos Information Disclosure Vulnerability",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01646,
            "epssPercentile": 0.74883,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21243",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21244",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21245",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21246",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21248",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01489,
            "epssPercentile": 0.72379,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21249",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21250",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21251",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02591,
            "epssPercentile": 0.84283,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21252",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21255",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21256",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21257",
            "title": "Windows WLAN AutoConfig Service Information Disclosure Vulnerability",
            "summary": "Windows WLAN AutoConfig Service Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00732,
            "epssPercentile": 0.51998,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21258",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21260",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55328,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21261",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21263",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21265",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21266",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21268",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01989,
            "epssPercentile": 0.79308,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21269",
            "title": "Windows HTML Platforms Security Feature Bypass Vulnerability",
            "summary": "Windows HTML Platforms Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.04593,
            "epssPercentile": 0.91034,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21270",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21272",
            "title": "Windows COM Server Information Disclosure Vulnerability",
            "summary": "Windows COM Server Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00706,
            "epssPercentile": 0.51085,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21273",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21274",
            "title": "Windows Event Tracing Denial of Service Vulnerability",
            "summary": "Windows Event Tracing Denial of Service Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00785,
            "epssPercentile": 0.53739,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21275",
            "title": "Windows App Package Installer Elevation of Privilege Vulnerability",
            "summary": "Windows App Package Installer Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00618,
            "epssPercentile": 0.47369,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21276",
            "title": "Windows MapUrlToZone Denial of Service Vulnerability",
            "summary": "Windows MapUrlToZone Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02421,
            "epssPercentile": 0.83098,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21277",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.38612,
            "epssPercentile": 0.98478,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21278",
            "title": "Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability",
            "summary": "Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0057,
            "epssPercentile": 0.45061,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21280",
            "title": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability",
            "summary": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49634,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21281",
            "title": "Microsoft COM for Windows Elevation of Privilege Vulnerability",
            "summary": "Microsoft COM for Windows Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00605,
            "epssPercentile": 0.46774,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21282",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21284",
            "title": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability",
            "summary": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49634,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21285",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.55686,
            "epssPercentile": 0.9897,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21286",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21287",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00549,
            "epssPercentile": 0.43984,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21288",
            "title": "Windows COM Server Information Disclosure Vulnerability",
            "summary": "Windows COM Server Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00706,
            "epssPercentile": 0.51085,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21289",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21290",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21291",
            "title": "Windows Direct Show Remote Code Execution Vulnerability",
            "summary": "Windows Direct Show Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01396,
            "epssPercentile": 0.70616,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21292",
            "title": "Windows Search Service Elevation of Privilege Vulnerability",
            "summary": "Windows Search Service Elevation of Privilege Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00825,
            "epssPercentile": 0.55027,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21293",
            "title": "Active Directory Domain Services Elevation of Privilege Vulnerability",
            "summary": "Active Directory Domain Services Elevation of Privilege Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.18825,
            "epssPercentile": 0.97091,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21294",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01209,
            "epssPercentile": 0.66385,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21295",
            "title": "SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability",
            "summary": "SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0161,
            "epssPercentile": 0.74316,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21296",
            "title": "BranchCache Remote Code Execution Vulnerability",
            "summary": "BranchCache Remote Code Execution Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00778,
            "epssPercentile": 0.53536,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21298",
            "title": "Windows OLE Remote Code Execution Vulnerability",
            "summary": "Windows OLE Remote Code Execution Vulnerability",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "CISA Vulnrichment records proof-of-concept exploitation in its SSVC data. BlackTree has not independently executed or validated exploit material.",
            "epss": 0.80912,
            "epssPercentile": 0.99602,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path and a public exploit reference; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21299",
            "title": "Windows Kerberos Security Feature Bypass Vulnerability",
            "summary": "Windows Kerberos Security Feature Bypass Vulnerability",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02212,
            "epssPercentile": 0.81462,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21300",
            "title": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "summary": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02531,
            "epssPercentile": 0.83874,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21301",
            "title": "Windows Geolocation Service Information Disclosure Vulnerability",
            "summary": "Windows Geolocation Service Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01564,
            "epssPercentile": 0.73648,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21302",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21303",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21305",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21306",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70986,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21307",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01909,
            "epssPercentile": 0.7842,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21308",
            "title": "Windows Themes Spoofing Vulnerability",
            "summary": "Windows Themes Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02208,
            "epssPercentile": 0.81432,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21310",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21312",
            "title": "Windows Smart Card Reader Information Disclosure Vulnerability",
            "summary": "Windows Smart Card Reader Information Disclosure Vulnerability",
            "score": 2.4,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00718,
            "epssPercentile": 0.51518,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21314",
            "title": "Windows SmartScreen Spoofing Vulnerability",
            "summary": "Windows SmartScreen Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01421,
            "epssPercentile": 0.71094,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21316",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58304,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21317",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0085,
            "epssPercentile": 0.55808,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21318",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21319",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21320",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21321",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21323",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0085,
            "epssPercentile": 0.55807,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21324",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21327",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21328",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01518,
            "epssPercentile": 0.72882,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21329",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01518,
            "epssPercentile": 0.72882,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21330",
            "title": "Windows Remote Desktop Services Denial of Service Vulnerability",
            "summary": "Windows Remote Desktop Services Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01961,
            "epssPercentile": 0.79002,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21331",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01019,
            "epssPercentile": 0.61089,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21332",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01474,
            "epssPercentile": 0.72107,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21333",
            "title": "Microsoft Windows Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows Hyper-V NT Kernel Integration VSP contains a heap-based buffer overflow vulnerability that allows a local attacker to gain SYSTEM privileges.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-01-14.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.09988,
            "epssPercentile": 0.95287,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-02-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21334",
            "title": "Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability",
            "summary": "Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-01-14.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01561,
            "epssPercentile": 0.73599,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-02-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21335",
            "title": "Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability",
            "summary": "Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-01-14.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0139,
            "epssPercentile": 0.70518,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-02-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21336",
            "title": "Windows Cryptographic Information Disclosure Vulnerability",
            "summary": "Windows Cryptographic Information Disclosure Vulnerability",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00631,
            "epssPercentile": 0.47982,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21338",
            "title": "GDI+ Remote Code Execution Vulnerability",
            "summary": "GDI+ Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39683,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21339",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21340",
            "title": "Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability",
            "summary": "Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00452,
            "epssPercentile": 0.37841,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21341",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00698,
            "epssPercentile": 0.50753,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21343",
            "title": "Windows Web Threat Defense User Service Information Disclosure Vulnerability",
            "summary": "Windows Web Threat Defense User Service Information Disclosure Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01348,
            "epssPercentile": 0.6961,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21370",
            "title": "Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability",
            "summary": "Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00475,
            "epssPercentile": 0.39377,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21374",
            "title": "Windows CSC Service Information Disclosure Vulnerability",
            "summary": "Windows CSC Service Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00587,
            "epssPercentile": 0.45949,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21378",
            "title": "Windows CSC Service Elevation of Privilege Vulnerability",
            "summary": "Windows CSC Service Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00564,
            "epssPercentile": 0.4479,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21382",
            "title": "Windows Graphics Component Elevation of Privilege Vulnerability",
            "summary": "Windows Graphics Component Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00503,
            "epssPercentile": 0.41206,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21389",
            "title": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "summary": "Uncontrolled resource consumption in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0194,
            "epssPercentile": 0.78785,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21409",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21411",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21413",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21417",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01171,
            "epssPercentile": 0.6537,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-esu-kb5050048",
      "slug": "microsoft-2025-01-esu-kb5050048",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5050048",
      "title": "Deploy Microsoft ESU security update KB5050048",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5050048",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)",
      "platform": "ESU",
      "release_version": "6.3.9600.22371",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21307",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 94 linked CVEs for Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation). Microsoft marks CVE-2025-21308 as publicly disclosed, without that disclosure alone changing the BlackTree action window.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 94,
        "ids": [
          "CVE-2025-21189",
          "CVE-2025-21210",
          "CVE-2025-21211",
          "CVE-2025-21213",
          "CVE-2025-21214",
          "CVE-2025-21215",
          "CVE-2025-21217",
          "CVE-2025-21218",
          "CVE-2025-21220",
          "CVE-2025-21223",
          "CVE-2025-21226",
          "CVE-2025-21227",
          "CVE-2025-21228",
          "CVE-2025-21229",
          "CVE-2025-21230",
          "CVE-2025-21231",
          "CVE-2025-21232",
          "CVE-2025-21233",
          "CVE-2025-21236",
          "CVE-2025-21237",
          "CVE-2025-21238",
          "CVE-2025-21240",
          "CVE-2025-21242",
          "CVE-2025-21243",
          "CVE-2025-21244",
          "CVE-2025-21245",
          "CVE-2025-21246",
          "CVE-2025-21249",
          "CVE-2025-21250",
          "CVE-2025-21251",
          "CVE-2025-21252",
          "CVE-2025-21255",
          "CVE-2025-21256",
          "CVE-2025-21258",
          "CVE-2025-21260",
          "CVE-2025-21261",
          "CVE-2025-21263",
          "CVE-2025-21265",
          "CVE-2025-21266",
          "CVE-2025-21268",
          "CVE-2025-21269",
          "CVE-2025-21270",
          "CVE-2025-21272",
          "CVE-2025-21273",
          "CVE-2025-21274",
          "CVE-2025-21276",
          "CVE-2025-21277",
          "CVE-2025-21278",
          "CVE-2025-21281",
          "CVE-2025-21282",
          "CVE-2025-21285",
          "CVE-2025-21286",
          "CVE-2025-21287",
          "CVE-2025-21288",
          "CVE-2025-21289",
          "CVE-2025-21290",
          "CVE-2025-21293",
          "CVE-2025-21294",
          "CVE-2025-21295",
          "CVE-2025-21296",
          "CVE-2025-21297",
          "CVE-2025-21298",
          "CVE-2025-21300",
          "CVE-2025-21302",
          "CVE-2025-21303",
          "CVE-2025-21305",
          "CVE-2025-21306",
          "CVE-2025-21307",
          "CVE-2025-21308",
          "CVE-2025-21309",
          "CVE-2025-21310",
          "CVE-2025-21312",
          "CVE-2025-21316",
          "CVE-2025-21318",
          "CVE-2025-21319",
          "CVE-2025-21320",
          "CVE-2025-21321",
          "CVE-2025-21324",
          "CVE-2025-21327",
          "CVE-2025-21328",
          "CVE-2025-21329",
          "CVE-2025-21331",
          "CVE-2025-21332",
          "CVE-2025-21336",
          "CVE-2025-21338",
          "CVE-2025-21339",
          "CVE-2025-21341",
          "CVE-2025-21374",
          "CVE-2025-21378",
          "CVE-2025-21389",
          "CVE-2025-21409",
          "CVE-2025-21411",
          "CVE-2025-21413",
          "CVE-2025-21417"
        ],
        "details": [
          {
            "id": "CVE-2025-21189",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02971,
            "epssPercentile": 0.86348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21210",
            "title": "Windows BitLocker Information Disclosure Vulnerability",
            "summary": "Windows BitLocker Information Disclosure Vulnerability",
            "score": 4.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01139,
            "epssPercentile": 0.64494,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21211",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Secure Boot Security Feature Bypass Vulnerability",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00773,
            "epssPercentile": 0.53349,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21213",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Secure Boot Security Feature Bypass Vulnerability",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0072,
            "epssPercentile": 0.51578,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21214",
            "title": "Windows BitLocker Information Disclosure Vulnerability",
            "summary": "Windows BitLocker Information Disclosure Vulnerability",
            "score": 4.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00713,
            "epssPercentile": 0.51333,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21215",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Secure Boot Security Feature Bypass Vulnerability",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00818,
            "epssPercentile": 0.5483,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21217",
            "title": "Windows NTLM Spoofing Vulnerability",
            "summary": "Windows NTLM Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01948,
            "epssPercentile": 0.78877,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21218",
            "title": "Windows Kerberos Denial of Service Vulnerability",
            "summary": "Windows Kerberos Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02589,
            "epssPercentile": 0.8425,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21220",
            "title": "Microsoft Message Queuing Information Disclosure Vulnerability",
            "summary": "Microsoft Message Queuing Information Disclosure Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02151,
            "epssPercentile": 0.80943,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21223",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01621,
            "epssPercentile": 0.74499,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21226",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00867,
            "epssPercentile": 0.5638,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21227",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21228",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21229",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21230",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02686,
            "epssPercentile": 0.84872,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21231",
            "title": "IP Helper Denial of Service Vulnerability",
            "summary": "IP Helper Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02591,
            "epssPercentile": 0.84283,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21232",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21233",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21236",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21237",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21238",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21240",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21242",
            "title": "Windows Kerberos Information Disclosure Vulnerability",
            "summary": "Windows Kerberos Information Disclosure Vulnerability",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01646,
            "epssPercentile": 0.74883,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21243",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21244",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21245",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21246",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21249",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21250",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21251",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02591,
            "epssPercentile": 0.84283,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21252",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21255",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21256",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21258",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21260",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55328,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21261",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21263",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21265",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21266",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21268",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01989,
            "epssPercentile": 0.79308,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21269",
            "title": "Windows HTML Platforms Security Feature Bypass Vulnerability",
            "summary": "Windows HTML Platforms Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.04593,
            "epssPercentile": 0.91034,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21270",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21272",
            "title": "Windows COM Server Information Disclosure Vulnerability",
            "summary": "Windows COM Server Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00706,
            "epssPercentile": 0.51085,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21273",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21274",
            "title": "Windows Event Tracing Denial of Service Vulnerability",
            "summary": "Windows Event Tracing Denial of Service Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00785,
            "epssPercentile": 0.53739,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21276",
            "title": "Windows MapUrlToZone Denial of Service Vulnerability",
            "summary": "Windows MapUrlToZone Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02421,
            "epssPercentile": 0.83098,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21277",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.38612,
            "epssPercentile": 0.98478,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21278",
            "title": "Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability",
            "summary": "Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0057,
            "epssPercentile": 0.45061,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21281",
            "title": "Microsoft COM for Windows Elevation of Privilege Vulnerability",
            "summary": "Microsoft COM for Windows Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00605,
            "epssPercentile": 0.46774,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21282",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21285",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.55686,
            "epssPercentile": 0.9897,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21286",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21287",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00549,
            "epssPercentile": 0.43984,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21288",
            "title": "Windows COM Server Information Disclosure Vulnerability",
            "summary": "Windows COM Server Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00706,
            "epssPercentile": 0.51085,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21289",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21290",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21293",
            "title": "Active Directory Domain Services Elevation of Privilege Vulnerability",
            "summary": "Active Directory Domain Services Elevation of Privilege Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.18825,
            "epssPercentile": 0.97091,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21294",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01209,
            "epssPercentile": 0.66385,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21295",
            "title": "SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability",
            "summary": "SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0161,
            "epssPercentile": 0.74316,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21296",
            "title": "BranchCache Remote Code Execution Vulnerability",
            "summary": "BranchCache Remote Code Execution Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00778,
            "epssPercentile": 0.53536,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21297",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01436,
            "epssPercentile": 0.71362,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21298",
            "title": "Windows OLE Remote Code Execution Vulnerability",
            "summary": "Windows OLE Remote Code Execution Vulnerability",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "CISA Vulnrichment records proof-of-concept exploitation in its SSVC data. BlackTree has not independently executed or validated exploit material.",
            "epss": 0.80912,
            "epssPercentile": 0.99602,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path and a public exploit reference; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21300",
            "title": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "summary": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02531,
            "epssPercentile": 0.83874,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21302",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21303",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21305",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21306",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70986,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21307",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01909,
            "epssPercentile": 0.7842,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21308",
            "title": "Windows Themes Spoofing Vulnerability",
            "summary": "Windows Themes Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02208,
            "epssPercentile": 0.81432,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21309",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.14979,
            "epssPercentile": 0.96482,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21310",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21312",
            "title": "Windows Smart Card Reader Information Disclosure Vulnerability",
            "summary": "Windows Smart Card Reader Information Disclosure Vulnerability",
            "score": 2.4,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00718,
            "epssPercentile": 0.51518,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21316",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58304,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21318",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21319",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21320",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21321",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21324",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21327",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21328",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01518,
            "epssPercentile": 0.72882,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21329",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01518,
            "epssPercentile": 0.72882,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21331",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01019,
            "epssPercentile": 0.61089,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21332",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01474,
            "epssPercentile": 0.72107,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21336",
            "title": "Windows Cryptographic Information Disclosure Vulnerability",
            "summary": "Windows Cryptographic Information Disclosure Vulnerability",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00631,
            "epssPercentile": 0.47982,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21338",
            "title": "GDI+ Remote Code Execution Vulnerability",
            "summary": "GDI+ Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39683,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21339",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21341",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00698,
            "epssPercentile": 0.50753,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21374",
            "title": "Windows CSC Service Information Disclosure Vulnerability",
            "summary": "Windows CSC Service Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00587,
            "epssPercentile": 0.45949,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21378",
            "title": "Windows CSC Service Elevation of Privilege Vulnerability",
            "summary": "Windows CSC Service Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00564,
            "epssPercentile": 0.4479,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21389",
            "title": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "summary": "Uncontrolled resource consumption in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0194,
            "epssPercentile": 0.78785,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21409",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21411",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21413",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21417",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01171,
            "epssPercentile": 0.6537,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-esu-kb5050049",
      "slug": "microsoft-2025-01-esu-kb5050049",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5050049",
      "title": "Deploy Microsoft ESU security update KB5050049",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5050049",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)",
      "platform": "ESU",
      "release_version": "6.1.7601.27520",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21307",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 78 linked CVEs for Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 78,
        "ids": [
          "CVE-2025-21189",
          "CVE-2025-21210",
          "CVE-2025-21214",
          "CVE-2025-21215",
          "CVE-2025-21217",
          "CVE-2025-21220",
          "CVE-2025-21223",
          "CVE-2025-21226",
          "CVE-2025-21227",
          "CVE-2025-21228",
          "CVE-2025-21230",
          "CVE-2025-21231",
          "CVE-2025-21232",
          "CVE-2025-21233",
          "CVE-2025-21236",
          "CVE-2025-21237",
          "CVE-2025-21238",
          "CVE-2025-21240",
          "CVE-2025-21242",
          "CVE-2025-21243",
          "CVE-2025-21244",
          "CVE-2025-21245",
          "CVE-2025-21246",
          "CVE-2025-21249",
          "CVE-2025-21250",
          "CVE-2025-21251",
          "CVE-2025-21252",
          "CVE-2025-21255",
          "CVE-2025-21256",
          "CVE-2025-21258",
          "CVE-2025-21260",
          "CVE-2025-21261",
          "CVE-2025-21263",
          "CVE-2025-21265",
          "CVE-2025-21266",
          "CVE-2025-21268",
          "CVE-2025-21269",
          "CVE-2025-21270",
          "CVE-2025-21272",
          "CVE-2025-21273",
          "CVE-2025-21276",
          "CVE-2025-21277",
          "CVE-2025-21282",
          "CVE-2025-21285",
          "CVE-2025-21286",
          "CVE-2025-21287",
          "CVE-2025-21288",
          "CVE-2025-21289",
          "CVE-2025-21290",
          "CVE-2025-21294",
          "CVE-2025-21295",
          "CVE-2025-21296",
          "CVE-2025-21297",
          "CVE-2025-21298",
          "CVE-2025-21300",
          "CVE-2025-21302",
          "CVE-2025-21303",
          "CVE-2025-21305",
          "CVE-2025-21306",
          "CVE-2025-21307",
          "CVE-2025-21310",
          "CVE-2025-21319",
          "CVE-2025-21320",
          "CVE-2025-21324",
          "CVE-2025-21327",
          "CVE-2025-21328",
          "CVE-2025-21329",
          "CVE-2025-21331",
          "CVE-2025-21332",
          "CVE-2025-21336",
          "CVE-2025-21338",
          "CVE-2025-21339",
          "CVE-2025-21341",
          "CVE-2025-21389",
          "CVE-2025-21409",
          "CVE-2025-21411",
          "CVE-2025-21413",
          "CVE-2025-21417"
        ],
        "details": [
          {
            "id": "CVE-2025-21189",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02971,
            "epssPercentile": 0.86348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21210",
            "title": "Windows BitLocker Information Disclosure Vulnerability",
            "summary": "Windows BitLocker Information Disclosure Vulnerability",
            "score": 4.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01139,
            "epssPercentile": 0.64494,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21214",
            "title": "Windows BitLocker Information Disclosure Vulnerability",
            "summary": "Windows BitLocker Information Disclosure Vulnerability",
            "score": 4.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00713,
            "epssPercentile": 0.51333,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21215",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Secure Boot Security Feature Bypass Vulnerability",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00818,
            "epssPercentile": 0.5483,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21217",
            "title": "Windows NTLM Spoofing Vulnerability",
            "summary": "Windows NTLM Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01948,
            "epssPercentile": 0.78877,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21220",
            "title": "Microsoft Message Queuing Information Disclosure Vulnerability",
            "summary": "Microsoft Message Queuing Information Disclosure Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02151,
            "epssPercentile": 0.80943,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21223",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01621,
            "epssPercentile": 0.74499,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21226",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00867,
            "epssPercentile": 0.5638,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21227",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21228",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21230",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02686,
            "epssPercentile": 0.84872,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21231",
            "title": "IP Helper Denial of Service Vulnerability",
            "summary": "IP Helper Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02591,
            "epssPercentile": 0.84283,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21232",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21233",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21236",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21237",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21238",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21240",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21242",
            "title": "Windows Kerberos Information Disclosure Vulnerability",
            "summary": "Windows Kerberos Information Disclosure Vulnerability",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01646,
            "epssPercentile": 0.74883,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21243",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21244",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21245",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21246",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21249",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21250",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21251",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02591,
            "epssPercentile": 0.84283,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21252",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21255",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21256",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21258",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21260",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55328,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21261",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21263",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21265",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21266",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21268",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01989,
            "epssPercentile": 0.79308,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21269",
            "title": "Windows HTML Platforms Security Feature Bypass Vulnerability",
            "summary": "Windows HTML Platforms Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.04593,
            "epssPercentile": 0.91034,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21270",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21272",
            "title": "Windows COM Server Information Disclosure Vulnerability",
            "summary": "Windows COM Server Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00706,
            "epssPercentile": 0.51085,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21273",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21276",
            "title": "Windows MapUrlToZone Denial of Service Vulnerability",
            "summary": "Windows MapUrlToZone Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02421,
            "epssPercentile": 0.83098,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21277",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.38612,
            "epssPercentile": 0.98478,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21282",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21285",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.55686,
            "epssPercentile": 0.9897,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21286",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21287",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00549,
            "epssPercentile": 0.43984,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21288",
            "title": "Windows COM Server Information Disclosure Vulnerability",
            "summary": "Windows COM Server Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00706,
            "epssPercentile": 0.51085,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21289",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21290",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21294",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01209,
            "epssPercentile": 0.66385,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21295",
            "title": "SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability",
            "summary": "SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0161,
            "epssPercentile": 0.74316,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21296",
            "title": "BranchCache Remote Code Execution Vulnerability",
            "summary": "BranchCache Remote Code Execution Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00778,
            "epssPercentile": 0.53536,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21297",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01436,
            "epssPercentile": 0.71362,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21298",
            "title": "Windows OLE Remote Code Execution Vulnerability",
            "summary": "Windows OLE Remote Code Execution Vulnerability",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "CISA Vulnrichment records proof-of-concept exploitation in its SSVC data. BlackTree has not independently executed or validated exploit material.",
            "epss": 0.80912,
            "epssPercentile": 0.99602,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path and a public exploit reference; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21300",
            "title": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "summary": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02531,
            "epssPercentile": 0.83874,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21302",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21303",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21305",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21306",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70986,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21307",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01909,
            "epssPercentile": 0.7842,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21310",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21319",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21320",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21324",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21327",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21328",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01518,
            "epssPercentile": 0.72882,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21329",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01518,
            "epssPercentile": 0.72882,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21331",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01019,
            "epssPercentile": 0.61089,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21332",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01474,
            "epssPercentile": 0.72107,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21336",
            "title": "Windows Cryptographic Information Disclosure Vulnerability",
            "summary": "Windows Cryptographic Information Disclosure Vulnerability",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00631,
            "epssPercentile": 0.47982,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21338",
            "title": "GDI+ Remote Code Execution Vulnerability",
            "summary": "GDI+ Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39683,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21339",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21341",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00698,
            "epssPercentile": 0.50753,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21389",
            "title": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "summary": "Uncontrolled resource consumption in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0194,
            "epssPercentile": 0.78785,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21409",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21411",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21413",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21417",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01171,
            "epssPercentile": 0.6537,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-esu-kb5050061",
      "slug": "microsoft-2025-01-esu-kb5050061",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5050061",
      "title": "Deploy Microsoft ESU security update KB5050061",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5050061",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more",
      "platform": "ESU",
      "release_version": "6.0.6003.23070",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21307",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 66 linked CVEs for Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 66,
        "ids": [
          "CVE-2025-21210",
          "CVE-2025-21214",
          "CVE-2025-21215",
          "CVE-2025-21217",
          "CVE-2025-21220",
          "CVE-2025-21223",
          "CVE-2025-21226",
          "CVE-2025-21227",
          "CVE-2025-21228",
          "CVE-2025-21230",
          "CVE-2025-21231",
          "CVE-2025-21232",
          "CVE-2025-21233",
          "CVE-2025-21236",
          "CVE-2025-21237",
          "CVE-2025-21238",
          "CVE-2025-21240",
          "CVE-2025-21243",
          "CVE-2025-21244",
          "CVE-2025-21245",
          "CVE-2025-21246",
          "CVE-2025-21249",
          "CVE-2025-21250",
          "CVE-2025-21251",
          "CVE-2025-21252",
          "CVE-2025-21255",
          "CVE-2025-21256",
          "CVE-2025-21258",
          "CVE-2025-21260",
          "CVE-2025-21261",
          "CVE-2025-21263",
          "CVE-2025-21265",
          "CVE-2025-21266",
          "CVE-2025-21270",
          "CVE-2025-21272",
          "CVE-2025-21273",
          "CVE-2025-21277",
          "CVE-2025-21282",
          "CVE-2025-21285",
          "CVE-2025-21286",
          "CVE-2025-21287",
          "CVE-2025-21288",
          "CVE-2025-21289",
          "CVE-2025-21290",
          "CVE-2025-21294",
          "CVE-2025-21298",
          "CVE-2025-21300",
          "CVE-2025-21302",
          "CVE-2025-21303",
          "CVE-2025-21305",
          "CVE-2025-21306",
          "CVE-2025-21307",
          "CVE-2025-21310",
          "CVE-2025-21320",
          "CVE-2025-21324",
          "CVE-2025-21327",
          "CVE-2025-21331",
          "CVE-2025-21336",
          "CVE-2025-21338",
          "CVE-2025-21339",
          "CVE-2025-21341",
          "CVE-2025-21389",
          "CVE-2025-21409",
          "CVE-2025-21411",
          "CVE-2025-21413",
          "CVE-2025-21417"
        ],
        "details": [
          {
            "id": "CVE-2025-21210",
            "title": "Windows BitLocker Information Disclosure Vulnerability",
            "summary": "Windows BitLocker Information Disclosure Vulnerability",
            "score": 4.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01139,
            "epssPercentile": 0.64494,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21214",
            "title": "Windows BitLocker Information Disclosure Vulnerability",
            "summary": "Windows BitLocker Information Disclosure Vulnerability",
            "score": 4.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00713,
            "epssPercentile": 0.51333,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21215",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Secure Boot Security Feature Bypass Vulnerability",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00818,
            "epssPercentile": 0.5483,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21217",
            "title": "Windows NTLM Spoofing Vulnerability",
            "summary": "Windows NTLM Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01948,
            "epssPercentile": 0.78877,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21220",
            "title": "Microsoft Message Queuing Information Disclosure Vulnerability",
            "summary": "Microsoft Message Queuing Information Disclosure Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02151,
            "epssPercentile": 0.80943,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21223",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01621,
            "epssPercentile": 0.74499,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21226",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00867,
            "epssPercentile": 0.5638,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21227",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21228",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21230",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02686,
            "epssPercentile": 0.84872,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21231",
            "title": "IP Helper Denial of Service Vulnerability",
            "summary": "IP Helper Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02591,
            "epssPercentile": 0.84283,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21232",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21233",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21236",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21237",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21238",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21240",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21243",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21244",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21245",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21246",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21249",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21250",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21251",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02591,
            "epssPercentile": 0.84283,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21252",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21255",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21256",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21258",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21260",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55328,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21261",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21263",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21265",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21266",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21270",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21272",
            "title": "Windows COM Server Information Disclosure Vulnerability",
            "summary": "Windows COM Server Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00706,
            "epssPercentile": 0.51085,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21273",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21277",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.38612,
            "epssPercentile": 0.98478,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21282",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21285",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.55686,
            "epssPercentile": 0.9897,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21286",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21287",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00549,
            "epssPercentile": 0.43984,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21288",
            "title": "Windows COM Server Information Disclosure Vulnerability",
            "summary": "Windows COM Server Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00706,
            "epssPercentile": 0.51085,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21289",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21290",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21294",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01209,
            "epssPercentile": 0.66385,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21298",
            "title": "Windows OLE Remote Code Execution Vulnerability",
            "summary": "Windows OLE Remote Code Execution Vulnerability",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "CISA Vulnrichment records proof-of-concept exploitation in its SSVC data. BlackTree has not independently executed or validated exploit material.",
            "epss": 0.80912,
            "epssPercentile": 0.99602,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path and a public exploit reference; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21300",
            "title": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "summary": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02531,
            "epssPercentile": 0.83874,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21302",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21303",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21305",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21306",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70986,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21307",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01909,
            "epssPercentile": 0.7842,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21310",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21320",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21324",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21327",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21331",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01019,
            "epssPercentile": 0.61089,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21336",
            "title": "Windows Cryptographic Information Disclosure Vulnerability",
            "summary": "Windows Cryptographic Information Disclosure Vulnerability",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00631,
            "epssPercentile": 0.47982,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21338",
            "title": "GDI+ Remote Code Execution Vulnerability",
            "summary": "GDI+ Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39683,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21339",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21341",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00698,
            "epssPercentile": 0.50753,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21389",
            "title": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "summary": "Uncontrolled resource consumption in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0194,
            "epssPercentile": 0.78785,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21409",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21411",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21413",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21417",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01171,
            "epssPercentile": 0.6537,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-esu-kb5050063",
      "slug": "microsoft-2025-01-esu-kb5050063",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5050063",
      "title": "Deploy Microsoft ESU security update KB5050063",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5050063",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more",
      "platform": "ESU",
      "release_version": "6.0.6003.23070",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21307",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 73 linked CVEs for Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 73,
        "ids": [
          "CVE-2025-21189",
          "CVE-2025-21210",
          "CVE-2025-21214",
          "CVE-2025-21215",
          "CVE-2025-21217",
          "CVE-2025-21220",
          "CVE-2025-21223",
          "CVE-2025-21226",
          "CVE-2025-21227",
          "CVE-2025-21228",
          "CVE-2025-21230",
          "CVE-2025-21231",
          "CVE-2025-21232",
          "CVE-2025-21233",
          "CVE-2025-21236",
          "CVE-2025-21237",
          "CVE-2025-21238",
          "CVE-2025-21240",
          "CVE-2025-21243",
          "CVE-2025-21244",
          "CVE-2025-21245",
          "CVE-2025-21246",
          "CVE-2025-21249",
          "CVE-2025-21250",
          "CVE-2025-21251",
          "CVE-2025-21252",
          "CVE-2025-21255",
          "CVE-2025-21256",
          "CVE-2025-21258",
          "CVE-2025-21260",
          "CVE-2025-21261",
          "CVE-2025-21263",
          "CVE-2025-21265",
          "CVE-2025-21266",
          "CVE-2025-21268",
          "CVE-2025-21269",
          "CVE-2025-21270",
          "CVE-2025-21272",
          "CVE-2025-21273",
          "CVE-2025-21276",
          "CVE-2025-21277",
          "CVE-2025-21282",
          "CVE-2025-21285",
          "CVE-2025-21286",
          "CVE-2025-21287",
          "CVE-2025-21288",
          "CVE-2025-21289",
          "CVE-2025-21290",
          "CVE-2025-21294",
          "CVE-2025-21298",
          "CVE-2025-21300",
          "CVE-2025-21302",
          "CVE-2025-21303",
          "CVE-2025-21305",
          "CVE-2025-21306",
          "CVE-2025-21307",
          "CVE-2025-21310",
          "CVE-2025-21320",
          "CVE-2025-21324",
          "CVE-2025-21327",
          "CVE-2025-21328",
          "CVE-2025-21329",
          "CVE-2025-21331",
          "CVE-2025-21332",
          "CVE-2025-21336",
          "CVE-2025-21338",
          "CVE-2025-21339",
          "CVE-2025-21341",
          "CVE-2025-21389",
          "CVE-2025-21409",
          "CVE-2025-21411",
          "CVE-2025-21413",
          "CVE-2025-21417"
        ],
        "details": [
          {
            "id": "CVE-2025-21189",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02971,
            "epssPercentile": 0.86348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21210",
            "title": "Windows BitLocker Information Disclosure Vulnerability",
            "summary": "Windows BitLocker Information Disclosure Vulnerability",
            "score": 4.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01139,
            "epssPercentile": 0.64494,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21214",
            "title": "Windows BitLocker Information Disclosure Vulnerability",
            "summary": "Windows BitLocker Information Disclosure Vulnerability",
            "score": 4.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00713,
            "epssPercentile": 0.51333,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21215",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Secure Boot Security Feature Bypass Vulnerability",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00818,
            "epssPercentile": 0.5483,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21217",
            "title": "Windows NTLM Spoofing Vulnerability",
            "summary": "Windows NTLM Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01948,
            "epssPercentile": 0.78877,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21220",
            "title": "Microsoft Message Queuing Information Disclosure Vulnerability",
            "summary": "Microsoft Message Queuing Information Disclosure Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02151,
            "epssPercentile": 0.80943,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21223",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01621,
            "epssPercentile": 0.74499,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21226",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00867,
            "epssPercentile": 0.5638,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21227",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21228",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21230",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02686,
            "epssPercentile": 0.84872,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21231",
            "title": "IP Helper Denial of Service Vulnerability",
            "summary": "IP Helper Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02591,
            "epssPercentile": 0.84283,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21232",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21233",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21236",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21237",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21238",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21240",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21243",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21244",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21245",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21246",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21249",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21250",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21251",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02591,
            "epssPercentile": 0.84283,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21252",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21255",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21256",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21258",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21260",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55328,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21261",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21263",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21265",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21266",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21268",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01989,
            "epssPercentile": 0.79308,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21269",
            "title": "Windows HTML Platforms Security Feature Bypass Vulnerability",
            "summary": "Windows HTML Platforms Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.04593,
            "epssPercentile": 0.91034,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21270",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21272",
            "title": "Windows COM Server Information Disclosure Vulnerability",
            "summary": "Windows COM Server Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00706,
            "epssPercentile": 0.51085,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21273",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21276",
            "title": "Windows MapUrlToZone Denial of Service Vulnerability",
            "summary": "Windows MapUrlToZone Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02421,
            "epssPercentile": 0.83098,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21277",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.38612,
            "epssPercentile": 0.98478,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21282",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21285",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.55686,
            "epssPercentile": 0.9897,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21286",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21287",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00549,
            "epssPercentile": 0.43984,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21288",
            "title": "Windows COM Server Information Disclosure Vulnerability",
            "summary": "Windows COM Server Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00706,
            "epssPercentile": 0.51085,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21289",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21290",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21294",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01209,
            "epssPercentile": 0.66385,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21298",
            "title": "Windows OLE Remote Code Execution Vulnerability",
            "summary": "Windows OLE Remote Code Execution Vulnerability",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "CISA Vulnrichment records proof-of-concept exploitation in its SSVC data. BlackTree has not independently executed or validated exploit material.",
            "epss": 0.80912,
            "epssPercentile": 0.99602,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path and a public exploit reference; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21300",
            "title": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "summary": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02531,
            "epssPercentile": 0.83874,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21302",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21303",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21305",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21306",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70986,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21307",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01909,
            "epssPercentile": 0.7842,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21310",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21320",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21324",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21327",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21328",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01518,
            "epssPercentile": 0.72882,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21329",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01518,
            "epssPercentile": 0.72882,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21331",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01019,
            "epssPercentile": 0.61089,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21332",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01474,
            "epssPercentile": 0.72107,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21336",
            "title": "Windows Cryptographic Information Disclosure Vulnerability",
            "summary": "Windows Cryptographic Information Disclosure Vulnerability",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00631,
            "epssPercentile": 0.47982,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21338",
            "title": "GDI+ Remote Code Execution Vulnerability",
            "summary": "GDI+ Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39683,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21339",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21341",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00698,
            "epssPercentile": 0.50753,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21389",
            "title": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "summary": "Uncontrolled resource consumption in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0194,
            "epssPercentile": 0.78785,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21409",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21411",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21413",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21417",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01171,
            "epssPercentile": 0.6537,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-microsoft-dynamics-msrc-2025-01-microsoft-dynamics-release-notes-power-automate-for-desktop",
      "slug": "microsoft-2025-01-microsoft-dynamics-msrc-2025-01-microsoft-dynamics-release-notes-power-automate-for-desktop",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-01-microsoft-dynamics-release-notes",
      "title": "Deploy Microsoft Microsoft Dynamics update for Power Automate for Desktop",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://apps.microsoft.com/detail/9nftch6j7fhv?launch=true&mode=full&hl=en-us&gl=us&ocid=bingwebsearch",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Power Automate for Desktop",
      "platform": "Microsoft Dynamics",
      "release_version": "2.52.62.25009",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21187",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Power Automate for Desktop exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Power Automate for Desktop.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21187"
        ],
        "details": [
          {
            "id": "CVE-2025-21187",
            "title": "Microsoft Power Automate Remote Code Execution Vulnerability",
            "summary": "Microsoft Power Automate Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00747,
            "epssPercentile": 0.52512,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-microsoft-office-kb5002595",
      "slug": "microsoft-2025-01-microsoft-office-kb5002595",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002595",
      "title": "Deploy Microsoft Microsoft Office security update KB5002595",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002595",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition)",
      "platform": "Microsoft Office",
      "release_version": "16.0.5483.1000",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21346",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21346"
        ],
        "details": [
          {
            "id": "CVE-2025-21346",
            "title": "Microsoft Office Security Feature Bypass Vulnerability",
            "summary": "Microsoft Office Security Feature Bypass Vulnerability",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00672,
            "epssPercentile": 0.4975,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-microsoft-office-kb5002656",
      "slug": "microsoft-2025-01-microsoft-office-kb5002656",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002656",
      "title": "Deploy Microsoft Microsoft Office security update KB5002656",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002656",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft Outlook 2016 (32-bit edition), Microsoft Outlook 2016 (64-bit edition)",
      "platform": "Microsoft Office",
      "release_version": "16.0.5483.1000",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 6.7,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21357",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Outlook 2016 (32-bit edition), Microsoft Outlook 2016 (64-bit edition) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Outlook 2016 (32-bit edition), Microsoft Outlook 2016 (64-bit edition).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21357"
        ],
        "details": [
          {
            "id": "CVE-2025-21357",
            "title": "Microsoft Outlook Remote Code Execution Vulnerability",
            "summary": "Microsoft Outlook Remote Code Execution Vulnerability",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00567,
            "epssPercentile": 0.44929,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-microsoft-office-kb5002666",
      "slug": "microsoft-2025-01-microsoft-office-kb5002666",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002666",
      "title": "Deploy Microsoft Microsoft Office security update KB5002666",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002666",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft SharePoint Server 2019",
      "platform": "Microsoft Office",
      "release_version": "16.0.10416.20041",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21344",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft SharePoint Server 2019 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft SharePoint Server 2019.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 3,
        "ids": [
          "CVE-2025-21344",
          "CVE-2025-21348",
          "CVE-2025-21393"
        ],
        "details": [
          {
            "id": "CVE-2025-21344",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00842,
            "epssPercentile": 0.55564,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21348",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "score": 7.2,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01807,
            "epssPercentile": 0.77128,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21393",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Microsoft SharePoint Server Spoofing Vulnerability",
            "score": 6.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0108,
            "epssPercentile": 0.62886,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-microsoft-office-kb5002667",
      "slug": "microsoft-2025-01-microsoft-office-kb5002667",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002667",
      "title": "Deploy Microsoft Microsoft Office security update KB5002667",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002667",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft SharePoint Server 2019",
      "platform": "Microsoft Office",
      "release_version": "16.0.10416.20041",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21344",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft SharePoint Server 2019 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft SharePoint Server 2019.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 3,
        "ids": [
          "CVE-2025-21344",
          "CVE-2025-21348",
          "CVE-2025-21393"
        ],
        "details": [
          {
            "id": "CVE-2025-21344",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00842,
            "epssPercentile": 0.55564,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21348",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "score": 7.2,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01807,
            "epssPercentile": 0.77128,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21393",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Microsoft SharePoint Server Spoofing Vulnerability",
            "score": 6.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0108,
            "epssPercentile": 0.62886,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-microsoft-office-kb5002670",
      "slug": "microsoft-2025-01-microsoft-office-kb5002670",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002670",
      "title": "Deploy Microsoft Microsoft Office security update KB5002670",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002670",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft Access 2016 (32-bit edition), Microsoft Access 2016 (64-bit edition)",
      "platform": "Microsoft Office",
      "release_version": "16.0.5483.1001",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21366",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Access 2016 (32-bit edition), Microsoft Access 2016 (64-bit edition) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Microsoft Access 2016 (32-bit edition), Microsoft Access 2016 (64-bit edition). Microsoft marks CVE-2025-21186, CVE-2025-21366 as publicly disclosed, without that disclosure alone changing the BlackTree action window.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 2,
        "ids": [
          "CVE-2025-21186",
          "CVE-2025-21366"
        ],
        "details": [
          {
            "id": "CVE-2025-21186",
            "title": "Microsoft Access Remote Code Execution Vulnerability",
            "summary": "Microsoft Access Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01139,
            "epssPercentile": 0.64495,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21366",
            "title": "Microsoft Access Remote Code Execution Vulnerability",
            "summary": "Microsoft Access Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01108,
            "epssPercentile": 0.63711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-microsoft-office-kb5002671",
      "slug": "microsoft-2025-01-microsoft-office-kb5002671",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002671",
      "title": "Deploy Microsoft Microsoft Office security update KB5002671",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002671",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "platform": "Microsoft Office",
      "release_version": "16.0.5483.1001",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21344",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft SharePoint Enterprise Server 2016 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft SharePoint Enterprise Server 2016.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 3,
        "ids": [
          "CVE-2025-21344",
          "CVE-2025-21348",
          "CVE-2025-21393"
        ],
        "details": [
          {
            "id": "CVE-2025-21344",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00842,
            "epssPercentile": 0.55564,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21348",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "score": 7.2,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01807,
            "epssPercentile": 0.77128,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21393",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Microsoft SharePoint Server Spoofing Vulnerability",
            "score": 6.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0108,
            "epssPercentile": 0.62886,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-microsoft-office-kb5002672",
      "slug": "microsoft-2025-01-microsoft-office-kb5002672",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002672",
      "title": "Deploy Microsoft Microsoft Office security update KB5002672",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002672",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "platform": "Microsoft Office",
      "release_version": "16.0.5483.1001",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21344",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft SharePoint Enterprise Server 2016 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft SharePoint Enterprise Server 2016.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 3,
        "ids": [
          "CVE-2025-21344",
          "CVE-2025-21348",
          "CVE-2025-21393"
        ],
        "details": [
          {
            "id": "CVE-2025-21344",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00842,
            "epssPercentile": 0.55564,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21348",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "score": 7.2,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01807,
            "epssPercentile": 0.77128,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21393",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Microsoft SharePoint Server Spoofing Vulnerability",
            "score": 6.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0108,
            "epssPercentile": 0.62886,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-microsoft-office-kb5002673",
      "slug": "microsoft-2025-01-microsoft-office-kb5002673",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002673",
      "title": "Deploy Microsoft Microsoft Office security update KB5002673",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002673",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft Excel 2016 (32-bit edition), Microsoft Excel 2016 (64-bit edition)",
      "platform": "Microsoft Office",
      "release_version": "16.0.5483.1001",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.4,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21362",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Excel 2016 (32-bit edition), Microsoft Excel 2016 (64-bit edition) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Excel 2016 (32-bit edition), Microsoft Excel 2016 (64-bit edition).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21362"
        ],
        "details": [
          {
            "id": "CVE-2025-21362",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Microsoft Excel Remote Code Execution Vulnerability",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00934,
            "epssPercentile": 0.58455,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-microsoft-office-kb5002675",
      "slug": "microsoft-2025-01-microsoft-office-kb5002675",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002675",
      "title": "Deploy Microsoft Microsoft Office security update KB5002675",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002675",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition)",
      "platform": "Microsoft Office",
      "release_version": "16.0.5483.1001",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21346",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21346"
        ],
        "details": [
          {
            "id": "CVE-2025-21346",
            "title": "Microsoft Office Security Feature Bypass Vulnerability",
            "summary": "Microsoft Office Security Feature Bypass Vulnerability",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00672,
            "epssPercentile": 0.4975,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-microsoft-office-kb5002676",
      "slug": "microsoft-2025-01-microsoft-office-kb5002676",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002676",
      "title": "Deploy Microsoft Microsoft Office security update KB5002676",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002676",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft SharePoint Server Subscription Edition",
      "platform": "Microsoft Office",
      "release_version": "16.0.17928.20356",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21344",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft SharePoint Server Subscription Edition exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft SharePoint Server Subscription Edition.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 3,
        "ids": [
          "CVE-2025-21344",
          "CVE-2025-21348",
          "CVE-2025-21393"
        ],
        "details": [
          {
            "id": "CVE-2025-21344",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00842,
            "epssPercentile": 0.55564,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21348",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "score": 7.2,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01807,
            "epssPercentile": 0.77128,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21393",
            "title": "Microsoft SharePoint Server Spoofing Vulnerability",
            "summary": "Microsoft SharePoint Server Spoofing Vulnerability",
            "score": 6.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0108,
            "epssPercentile": 0.62886,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-microsoft-office-kb5002677",
      "slug": "microsoft-2025-01-microsoft-office-kb5002677",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002677",
      "title": "Deploy Microsoft Microsoft Office security update KB5002677",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002677",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Office Online Server",
      "platform": "Microsoft Office",
      "release_version": "16.0.10416.20047",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.4,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21362",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Office Online Server exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Office Online Server.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 2,
        "ids": [
          "CVE-2025-21354",
          "CVE-2025-21362"
        ],
        "details": [
          {
            "id": "CVE-2025-21354",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Microsoft Excel Remote Code Execution Vulnerability",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00941,
            "epssPercentile": 0.58669,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21362",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Microsoft Excel Remote Code Execution Vulnerability",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00934,
            "epssPercentile": 0.58455,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-microsoft-office-kb5002688",
      "slug": "microsoft-2025-01-microsoft-office-kb5002688",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002688",
      "title": "Deploy Microsoft Microsoft Office security update KB5002688",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002688",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft Access 2016 (32-bit edition), Microsoft Access 2016 (64-bit edition)",
      "platform": "Microsoft Office",
      "release_version": "16.0.5487.1000",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21395",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Access 2016 (32-bit edition), Microsoft Access 2016 (64-bit edition) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Access 2016 (32-bit edition), Microsoft Access 2016 (64-bit edition). Microsoft marks CVE-2025-21395 as publicly disclosed, without that disclosure alone changing the BlackTree action window.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21395"
        ],
        "details": [
          {
            "id": "CVE-2025-21395",
            "title": "Microsoft Access Remote Code Execution Vulnerability",
            "summary": "Microsoft Access Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01017,
            "epssPercentile": 0.61044,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-microsoft-office-msrc-2025-01-microsoft-office-click-to-run-microsoft-365-apps-for-enterprise-for-32-bit-systems-microsoft-365-apps-for-enterprise-for-64-bit-systems-micr",
      "slug": "microsoft-2025-01-microsoft-office-msrc-2025-01-microsoft-office-click-to-run-microsoft-365-apps-for-enterprise-for-32-bit-systems-microsoft-365-apps-for-enterprise-for-64-bit-systems-micr",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-01-microsoft-office-click-to-run",
      "title": "Deploy Microsoft Microsoft Office update for Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office 2019 for 32-bit editions, plus 5 more",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://msrc.microsoft.com/update-guide/releaseNote/2025-Jan",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office 2019 for 32-bit editions, plus 5 more",
      "platform": "Microsoft Office",
      "release_version": "https://aka.ms/OfficeSecurityReleases",
      "action_type": "deploy-patch",
      "restart_required": "no",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.4,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21362",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "The reviewed source does not require a restart.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office 2019 for 32-bit editions, plus 5 more exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 12 linked CVEs for Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office 2019 for 32-bit editions, plus 5 more. Microsoft marks CVE-2025-21186, CVE-2025-21366, CVE-2025-21395 as publicly disclosed, without that disclosure alone changing the BlackTree action window.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 12,
        "ids": [
          "CVE-2025-21186",
          "CVE-2025-21345",
          "CVE-2025-21346",
          "CVE-2025-21354",
          "CVE-2025-21356",
          "CVE-2025-21357",
          "CVE-2025-21362",
          "CVE-2025-21363",
          "CVE-2025-21364",
          "CVE-2025-21365",
          "CVE-2025-21366",
          "CVE-2025-21395"
        ],
        "details": [
          {
            "id": "CVE-2025-21186",
            "title": "Microsoft Access Remote Code Execution Vulnerability",
            "summary": "Microsoft Access Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01139,
            "epssPercentile": 0.64495,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21345",
            "title": "Microsoft Office Visio Remote Code Execution Vulnerability",
            "summary": "Microsoft Office Visio Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00588,
            "epssPercentile": 0.45982,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21346",
            "title": "Microsoft Office Security Feature Bypass Vulnerability",
            "summary": "Microsoft Office Security Feature Bypass Vulnerability",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00672,
            "epssPercentile": 0.4975,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21354",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Microsoft Excel Remote Code Execution Vulnerability",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00941,
            "epssPercentile": 0.58669,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21356",
            "title": "Microsoft Office Visio Remote Code Execution Vulnerability",
            "summary": "Microsoft Office Visio Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00721,
            "epssPercentile": 0.51615,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21357",
            "title": "Microsoft Outlook Remote Code Execution Vulnerability",
            "summary": "Microsoft Outlook Remote Code Execution Vulnerability",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00567,
            "epssPercentile": 0.44929,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21362",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Microsoft Excel Remote Code Execution Vulnerability",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00934,
            "epssPercentile": 0.58455,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21363",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Microsoft Word Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00755,
            "epssPercentile": 0.52783,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21364",
            "title": "Microsoft Excel Security Feature Bypass Vulnerability",
            "summary": "Microsoft Excel Security Feature Bypass Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01596,
            "epssPercentile": 0.74117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21365",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Microsoft Office Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00935,
            "epssPercentile": 0.5849,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21366",
            "title": "Microsoft Access Remote Code Execution Vulnerability",
            "summary": "Microsoft Access Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01108,
            "epssPercentile": 0.63711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21395",
            "title": "Microsoft Access Remote Code Execution Vulnerability",
            "summary": "Microsoft Access Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01017,
            "epssPercentile": 0.61044,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-microsoft-office-msrc-2025-01-microsoft-office-release-notes-microsoft-office-ltsc-for-mac-2021",
      "slug": "microsoft-2025-01-microsoft-office-msrc-2025-01-microsoft-office-release-notes-microsoft-office-ltsc-for-mac-2021",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-01-microsoft-office-release-notes",
      "title": "Deploy Microsoft Microsoft Office update for Microsoft Office LTSC for Mac 2021",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://go.microsoft.com/fwlink/p/?linkid=831049",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft Office LTSC for Mac 2021",
      "platform": "Microsoft Office",
      "release_version": "16.93.25011212",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.4,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21362",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Office LTSC for Mac 2021 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 6 linked CVEs for Microsoft Office LTSC for Mac 2021.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 6,
        "ids": [
          "CVE-2025-21338",
          "CVE-2025-21354",
          "CVE-2025-21361",
          "CVE-2025-21362",
          "CVE-2025-21363",
          "CVE-2025-21402"
        ],
        "details": [
          {
            "id": "CVE-2025-21338",
            "title": "GDI+ Remote Code Execution Vulnerability",
            "summary": "GDI+ Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39683,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21354",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Microsoft Excel Remote Code Execution Vulnerability",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00941,
            "epssPercentile": 0.58669,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21361",
            "title": "Microsoft Outlook Remote Code Execution Vulnerability",
            "summary": "Microsoft Outlook Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00747,
            "epssPercentile": 0.52512,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21362",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Microsoft Excel Remote Code Execution Vulnerability",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00934,
            "epssPercentile": 0.58455,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21363",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Microsoft Word Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00755,
            "epssPercentile": 0.52783,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21402",
            "title": "Microsoft Office OneNote Remote Code Execution Vulnerability",
            "summary": "Microsoft Office OneNote Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0065,
            "epssPercentile": 0.48893,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-microsoft-office-msrc-2025-01-microsoft-office-release-notes-microsoft-office-ltsc-for-mac-2024",
      "slug": "microsoft-2025-01-microsoft-office-msrc-2025-01-microsoft-office-release-notes-microsoft-office-ltsc-for-mac-2024",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-01-microsoft-office-release-notes",
      "title": "Deploy Microsoft Microsoft Office update for Microsoft Office LTSC for Mac 2024",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://go.microsoft.com/fwlink/p/?linkid=831049",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft Office LTSC for Mac 2024",
      "platform": "Microsoft Office",
      "release_version": "16.93.25011212",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.4,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21362",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Office LTSC for Mac 2024 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 6 linked CVEs for Microsoft Office LTSC for Mac 2024.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 6,
        "ids": [
          "CVE-2025-21338",
          "CVE-2025-21354",
          "CVE-2025-21361",
          "CVE-2025-21362",
          "CVE-2025-21363",
          "CVE-2025-21402"
        ],
        "details": [
          {
            "id": "CVE-2025-21338",
            "title": "GDI+ Remote Code Execution Vulnerability",
            "summary": "GDI+ Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39683,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21354",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Microsoft Excel Remote Code Execution Vulnerability",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00941,
            "epssPercentile": 0.58669,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21361",
            "title": "Microsoft Outlook Remote Code Execution Vulnerability",
            "summary": "Microsoft Outlook Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00747,
            "epssPercentile": 0.52512,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21362",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Microsoft Excel Remote Code Execution Vulnerability",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00934,
            "epssPercentile": 0.58455,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21363",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Microsoft Word Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00755,
            "epssPercentile": 0.52783,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21402",
            "title": "Microsoft Office OneNote Remote Code Execution Vulnerability",
            "summary": "Microsoft Office OneNote Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0065,
            "epssPercentile": 0.48893,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-microsoft-office-msrc-2025-01-microsoft-office-release-notes-microsoft-office-for-mac",
      "slug": "microsoft-2025-01-microsoft-office-msrc-2025-01-microsoft-office-release-notes-microsoft-office-for-mac",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-01-microsoft-office-release-notes",
      "title": "Deploy Microsoft Microsoft Office update for Microsoft Office for Mac",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://go.microsoft.com/fwlink/p/?linkid=831049",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft Office for Mac",
      "platform": "Microsoft Office",
      "release_version": "16.93.25011212",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21338",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Office for Mac exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Office for Mac.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21338"
        ],
        "details": [
          {
            "id": "CVE-2025-21338",
            "title": "GDI+ Remote Code Execution Vulnerability",
            "summary": "GDI+ Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39683,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-microsoft-office-msrc-2025-01-microsoft-office-release-notes-microsoft-office-for-ios",
      "slug": "microsoft-2025-01-microsoft-office-msrc-2025-01-microsoft-office-release-notes-microsoft-office-for-ios",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-01-microsoft-office-release-notes",
      "title": "Deploy Microsoft Microsoft Office update for Microsoft Office for iOS",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://apps.apple.com/us/app/microsoft-365-office/id541164041",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft Office for iOS",
      "platform": "Microsoft Office",
      "release_version": "2.93.24123014",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21338",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Office for iOS exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Office for iOS.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21338"
        ],
        "details": [
          {
            "id": "CVE-2025-21338",
            "title": "GDI+ Remote Code Execution Vulnerability",
            "summary": "GDI+ Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39683,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-microsoft-office-msrc-2025-01-microsoft-office-release-notes-microsoft-office-for-android",
      "slug": "microsoft-2025-01-microsoft-office-msrc-2025-01-microsoft-office-release-notes-microsoft-office-for-android",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-01-microsoft-office-release-notes",
      "title": "Deploy Microsoft Microsoft Office update for Microsoft Office for Android",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://play.google.com/store/apps/details?id=com.microsoft.office.officehubrow",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft Office for Android",
      "platform": "Microsoft Office",
      "release_version": "16.0.18429.20000",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21338",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Office for Android exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Office for Android.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21338"
        ],
        "details": [
          {
            "id": "CVE-2025-21338",
            "title": "GDI+ Remote Code Execution Vulnerability",
            "summary": "GDI+ Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39683,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-microsoft-office-msrc-2025-01-microsoft-office-release-notes-microsoft-office-for-universal",
      "slug": "microsoft-2025-01-microsoft-office-msrc-2025-01-microsoft-office-release-notes-microsoft-office-for-universal",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-01-microsoft-office-release-notes",
      "title": "Deploy Microsoft Microsoft Office update for Microsoft Office for Universal",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/en-us/account-billing/get-updates-for-apps-and-games-in-microsoft-store-a1fe19c0-532d-ec47-7035-d1c5a1dd464f",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft Office for Universal",
      "platform": "Microsoft Office",
      "release_version": "16.0.14326.22175",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21338",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Office for Universal exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Office for Universal.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21338"
        ],
        "details": [
          {
            "id": "CVE-2025-21338",
            "title": "GDI+ Remote Code Execution Vulnerability",
            "summary": "GDI+ Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39683,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-microsoft-office-msrc-2025-01-microsoft-office-release-notes-microsoft-autoupdate-for-mac",
      "slug": "microsoft-2025-01-microsoft-office-msrc-2025-01-microsoft-office-release-notes-microsoft-autoupdate-for-mac",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-01-microsoft-office-release-notes",
      "title": "Deploy Microsoft Microsoft Office update for Microsoft AutoUpdate for Mac",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://officecdnmac.microsoft.com/pr/C1297A47-86C4-4C1F-97FA-950631F94777/MacAutoupdate/Microsoft_AutoUpdate_4.77.24121924_Updater.pkg",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft AutoUpdate for Mac",
      "platform": "Microsoft Office",
      "release_version": "4.76",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21360",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft AutoUpdate for Mac exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft AutoUpdate for Mac.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21360"
        ],
        "details": [
          {
            "id": "CVE-2025-21360",
            "title": "Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability",
            "summary": "Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00449,
            "epssPercentile": 0.37635,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-microsoft-office-msrc-2025-01-microsoft-office-release-notes-microsoft-outlook-for-mac",
      "slug": "microsoft-2025-01-microsoft-office-msrc-2025-01-microsoft-office-release-notes-microsoft-outlook-for-mac",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-01-microsoft-office-release-notes",
      "title": "Deploy Microsoft Microsoft Office update for Microsoft Outlook for Mac",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://go.microsoft.com/fwlink/p/?linkid=831049",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft Outlook for Mac",
      "platform": "Microsoft Office",
      "release_version": "16.93",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21361",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Outlook for Mac exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Outlook for Mac.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21361"
        ],
        "details": [
          {
            "id": "CVE-2025-21361",
            "title": "Microsoft Outlook Remote Code Execution Vulnerability",
            "summary": "Microsoft Outlook Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00747,
            "epssPercentile": 0.52512,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-microsoft-office-msrc-2025-01-microsoft-office-release-notes-microsoft-onenote-for-mac",
      "slug": "microsoft-2025-01-microsoft-office-msrc-2025-01-microsoft-office-release-notes-microsoft-onenote-for-mac",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-01-microsoft-office-release-notes",
      "title": "Deploy Microsoft Microsoft Office update for Microsoft OneNote for Mac",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://go.microsoft.com/fwlink/p/?linkid=831049",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Microsoft OneNote for Mac",
      "platform": "Microsoft Office",
      "release_version": "16.92.24120731",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21402",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft OneNote for Mac exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft OneNote for Mac.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21402"
        ],
        "details": [
          {
            "id": "CVE-2025-21402",
            "title": "Microsoft Office OneNote Remote Code Execution Vulnerability",
            "summary": "Microsoft Office OneNote Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0065,
            "epssPercentile": 0.48893,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-windows-kb5049981",
      "slug": "microsoft-2025-01-windows-kb5049981",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5049981",
      "title": "Deploy Microsoft Windows security update KB5049981",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5049981",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems",
      "platform": "Windows",
      "release_version": "10.0.19044.5371",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21307",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 119 linked CVEs for Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems. Microsoft reports exploitation for CVE-2025-21333, CVE-2025-21334, CVE-2025-21335.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 119,
        "ids": [
          "CVE-2025-21189",
          "CVE-2025-21202",
          "CVE-2025-21207",
          "CVE-2025-21210",
          "CVE-2025-21211",
          "CVE-2025-21213",
          "CVE-2025-21214",
          "CVE-2025-21215",
          "CVE-2025-21217",
          "CVE-2025-21219",
          "CVE-2025-21220",
          "CVE-2025-21223",
          "CVE-2025-21224",
          "CVE-2025-21226",
          "CVE-2025-21227",
          "CVE-2025-21228",
          "CVE-2025-21229",
          "CVE-2025-21230",
          "CVE-2025-21231",
          "CVE-2025-21232",
          "CVE-2025-21233",
          "CVE-2025-21234",
          "CVE-2025-21235",
          "CVE-2025-21236",
          "CVE-2025-21237",
          "CVE-2025-21238",
          "CVE-2025-21239",
          "CVE-2025-21240",
          "CVE-2025-21241",
          "CVE-2025-21242",
          "CVE-2025-21243",
          "CVE-2025-21244",
          "CVE-2025-21245",
          "CVE-2025-21246",
          "CVE-2025-21248",
          "CVE-2025-21249",
          "CVE-2025-21250",
          "CVE-2025-21251",
          "CVE-2025-21252",
          "CVE-2025-21255",
          "CVE-2025-21256",
          "CVE-2025-21257",
          "CVE-2025-21258",
          "CVE-2025-21260",
          "CVE-2025-21261",
          "CVE-2025-21263",
          "CVE-2025-21265",
          "CVE-2025-21266",
          "CVE-2025-21268",
          "CVE-2025-21269",
          "CVE-2025-21270",
          "CVE-2025-21271",
          "CVE-2025-21272",
          "CVE-2025-21273",
          "CVE-2025-21274",
          "CVE-2025-21275",
          "CVE-2025-21276",
          "CVE-2025-21277",
          "CVE-2025-21278",
          "CVE-2025-21280",
          "CVE-2025-21281",
          "CVE-2025-21282",
          "CVE-2025-21284",
          "CVE-2025-21285",
          "CVE-2025-21286",
          "CVE-2025-21287",
          "CVE-2025-21288",
          "CVE-2025-21289",
          "CVE-2025-21290",
          "CVE-2025-21291",
          "CVE-2025-21292",
          "CVE-2025-21293",
          "CVE-2025-21294",
          "CVE-2025-21295",
          "CVE-2025-21296",
          "CVE-2025-21298",
          "CVE-2025-21299",
          "CVE-2025-21300",
          "CVE-2025-21301",
          "CVE-2025-21302",
          "CVE-2025-21303",
          "CVE-2025-21304",
          "CVE-2025-21305",
          "CVE-2025-21306",
          "CVE-2025-21307",
          "CVE-2025-21308",
          "CVE-2025-21310",
          "CVE-2025-21312",
          "CVE-2025-21314",
          "CVE-2025-21316",
          "CVE-2025-21317",
          "CVE-2025-21318",
          "CVE-2025-21319",
          "CVE-2025-21320",
          "CVE-2025-21321",
          "CVE-2025-21323",
          "CVE-2025-21324",
          "CVE-2025-21327",
          "CVE-2025-21328",
          "CVE-2025-21329",
          "CVE-2025-21330",
          "CVE-2025-21331",
          "CVE-2025-21332",
          "CVE-2025-21333",
          "CVE-2025-21334",
          "CVE-2025-21335",
          "CVE-2025-21336",
          "CVE-2025-21338",
          "CVE-2025-21339",
          "CVE-2025-21340",
          "CVE-2025-21341",
          "CVE-2025-21374",
          "CVE-2025-21378",
          "CVE-2025-21382",
          "CVE-2025-21389",
          "CVE-2025-21409",
          "CVE-2025-21411",
          "CVE-2025-21413",
          "CVE-2025-21417"
        ],
        "details": [
          {
            "id": "CVE-2025-21189",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02971,
            "epssPercentile": 0.86348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21202",
            "title": "Windows Recovery Environment Agent Elevation of Privilege Vulnerability",
            "summary": "Windows Recovery Environment Agent Elevation of Privilege Vulnerability",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0088,
            "epssPercentile": 0.56753,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21207",
            "title": "Windows Connected Devices Platform Service (Cdpsvc) Denial of Service Vulnerability",
            "summary": "Windows Connected Devices Platform Service (Cdpsvc) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02108,
            "epssPercentile": 0.80554,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21210",
            "title": "Windows BitLocker Information Disclosure Vulnerability",
            "summary": "Windows BitLocker Information Disclosure Vulnerability",
            "score": 4.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01139,
            "epssPercentile": 0.64494,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21211",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Secure Boot Security Feature Bypass Vulnerability",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00773,
            "epssPercentile": 0.53349,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21213",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Secure Boot Security Feature Bypass Vulnerability",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0072,
            "epssPercentile": 0.51578,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21214",
            "title": "Windows BitLocker Information Disclosure Vulnerability",
            "summary": "Windows BitLocker Information Disclosure Vulnerability",
            "score": 4.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00713,
            "epssPercentile": 0.51333,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21215",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Secure Boot Security Feature Bypass Vulnerability",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00818,
            "epssPercentile": 0.5483,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21217",
            "title": "Windows NTLM Spoofing Vulnerability",
            "summary": "Windows NTLM Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01948,
            "epssPercentile": 0.78877,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21219",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03017,
            "epssPercentile": 0.86549,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21220",
            "title": "Microsoft Message Queuing Information Disclosure Vulnerability",
            "summary": "Microsoft Message Queuing Information Disclosure Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02151,
            "epssPercentile": 0.80943,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21223",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01621,
            "epssPercentile": 0.74499,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21224",
            "title": "Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability",
            "summary": "Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01908,
            "epssPercentile": 0.78413,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21226",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00867,
            "epssPercentile": 0.5638,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21227",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21228",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21229",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21230",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02686,
            "epssPercentile": 0.84872,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21231",
            "title": "IP Helper Denial of Service Vulnerability",
            "summary": "IP Helper Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02591,
            "epssPercentile": 0.84283,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21232",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21233",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21234",
            "title": "Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability",
            "summary": "Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00598,
            "epssPercentile": 0.46439,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21235",
            "title": "Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability",
            "summary": "Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00596,
            "epssPercentile": 0.46331,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21236",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21237",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21238",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21239",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01489,
            "epssPercentile": 0.7238,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21240",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21241",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01489,
            "epssPercentile": 0.7238,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21242",
            "title": "Windows Kerberos Information Disclosure Vulnerability",
            "summary": "Windows Kerberos Information Disclosure Vulnerability",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01646,
            "epssPercentile": 0.74883,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21243",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21244",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21245",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21246",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21248",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01489,
            "epssPercentile": 0.72379,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21249",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21250",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21251",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02591,
            "epssPercentile": 0.84283,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21252",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21255",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21256",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21257",
            "title": "Windows WLAN AutoConfig Service Information Disclosure Vulnerability",
            "summary": "Windows WLAN AutoConfig Service Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00732,
            "epssPercentile": 0.51998,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21258",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21260",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55328,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21261",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21263",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21265",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21266",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21268",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01989,
            "epssPercentile": 0.79308,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21269",
            "title": "Windows HTML Platforms Security Feature Bypass Vulnerability",
            "summary": "Windows HTML Platforms Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.04593,
            "epssPercentile": 0.91034,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21270",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21271",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0054,
            "epssPercentile": 0.43498,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21272",
            "title": "Windows COM Server Information Disclosure Vulnerability",
            "summary": "Windows COM Server Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00706,
            "epssPercentile": 0.51085,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21273",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21274",
            "title": "Windows Event Tracing Denial of Service Vulnerability",
            "summary": "Windows Event Tracing Denial of Service Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00785,
            "epssPercentile": 0.53739,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21275",
            "title": "Windows App Package Installer Elevation of Privilege Vulnerability",
            "summary": "Windows App Package Installer Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00618,
            "epssPercentile": 0.47369,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21276",
            "title": "Windows MapUrlToZone Denial of Service Vulnerability",
            "summary": "Windows MapUrlToZone Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02421,
            "epssPercentile": 0.83098,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21277",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.38612,
            "epssPercentile": 0.98478,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21278",
            "title": "Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability",
            "summary": "Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0057,
            "epssPercentile": 0.45061,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21280",
            "title": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability",
            "summary": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49634,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21281",
            "title": "Microsoft COM for Windows Elevation of Privilege Vulnerability",
            "summary": "Microsoft COM for Windows Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00605,
            "epssPercentile": 0.46774,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21282",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21284",
            "title": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability",
            "summary": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49634,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21285",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.55686,
            "epssPercentile": 0.9897,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21286",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21287",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00549,
            "epssPercentile": 0.43984,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21288",
            "title": "Windows COM Server Information Disclosure Vulnerability",
            "summary": "Windows COM Server Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00706,
            "epssPercentile": 0.51085,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21289",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21290",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21291",
            "title": "Windows Direct Show Remote Code Execution Vulnerability",
            "summary": "Windows Direct Show Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01396,
            "epssPercentile": 0.70616,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21292",
            "title": "Windows Search Service Elevation of Privilege Vulnerability",
            "summary": "Windows Search Service Elevation of Privilege Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00825,
            "epssPercentile": 0.55027,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21293",
            "title": "Active Directory Domain Services Elevation of Privilege Vulnerability",
            "summary": "Active Directory Domain Services Elevation of Privilege Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.18825,
            "epssPercentile": 0.97091,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21294",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01209,
            "epssPercentile": 0.66385,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21295",
            "title": "SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability",
            "summary": "SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0161,
            "epssPercentile": 0.74316,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21296",
            "title": "BranchCache Remote Code Execution Vulnerability",
            "summary": "BranchCache Remote Code Execution Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00778,
            "epssPercentile": 0.53536,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21298",
            "title": "Windows OLE Remote Code Execution Vulnerability",
            "summary": "Windows OLE Remote Code Execution Vulnerability",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "CISA Vulnrichment records proof-of-concept exploitation in its SSVC data. BlackTree has not independently executed or validated exploit material.",
            "epss": 0.80912,
            "epssPercentile": 0.99602,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path and a public exploit reference; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21299",
            "title": "Windows Kerberos Security Feature Bypass Vulnerability",
            "summary": "Windows Kerberos Security Feature Bypass Vulnerability",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02212,
            "epssPercentile": 0.81462,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21300",
            "title": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "summary": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02531,
            "epssPercentile": 0.83874,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21301",
            "title": "Windows Geolocation Service Information Disclosure Vulnerability",
            "summary": "Windows Geolocation Service Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01564,
            "epssPercentile": 0.73648,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21302",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21303",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21304",
            "title": "Microsoft DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Microsoft DWM Core Library Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00604,
            "epssPercentile": 0.46711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21305",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21306",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70986,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21307",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01909,
            "epssPercentile": 0.7842,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21308",
            "title": "Windows Themes Spoofing Vulnerability",
            "summary": "Windows Themes Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02208,
            "epssPercentile": 0.81432,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21310",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21312",
            "title": "Windows Smart Card Reader Information Disclosure Vulnerability",
            "summary": "Windows Smart Card Reader Information Disclosure Vulnerability",
            "score": 2.4,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00718,
            "epssPercentile": 0.51518,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21314",
            "title": "Windows SmartScreen Spoofing Vulnerability",
            "summary": "Windows SmartScreen Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01421,
            "epssPercentile": 0.71094,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21316",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58304,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21317",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0085,
            "epssPercentile": 0.55808,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21318",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21319",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21320",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21321",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21323",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0085,
            "epssPercentile": 0.55807,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21324",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21327",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21328",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01518,
            "epssPercentile": 0.72882,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21329",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01518,
            "epssPercentile": 0.72882,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21330",
            "title": "Windows Remote Desktop Services Denial of Service Vulnerability",
            "summary": "Windows Remote Desktop Services Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01961,
            "epssPercentile": 0.79002,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21331",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01019,
            "epssPercentile": 0.61089,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21332",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01474,
            "epssPercentile": 0.72107,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21333",
            "title": "Microsoft Windows Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows Hyper-V NT Kernel Integration VSP contains a heap-based buffer overflow vulnerability that allows a local attacker to gain SYSTEM privileges.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-01-14.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.09988,
            "epssPercentile": 0.95287,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-02-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21334",
            "title": "Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability",
            "summary": "Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-01-14.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01561,
            "epssPercentile": 0.73599,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-02-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21335",
            "title": "Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability",
            "summary": "Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-01-14.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0139,
            "epssPercentile": 0.70518,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-02-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21336",
            "title": "Windows Cryptographic Information Disclosure Vulnerability",
            "summary": "Windows Cryptographic Information Disclosure Vulnerability",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00631,
            "epssPercentile": 0.47982,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21338",
            "title": "GDI+ Remote Code Execution Vulnerability",
            "summary": "GDI+ Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39683,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21339",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21340",
            "title": "Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability",
            "summary": "Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00452,
            "epssPercentile": 0.37841,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21341",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00698,
            "epssPercentile": 0.50753,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21374",
            "title": "Windows CSC Service Information Disclosure Vulnerability",
            "summary": "Windows CSC Service Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00587,
            "epssPercentile": 0.45949,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21378",
            "title": "Windows CSC Service Elevation of Privilege Vulnerability",
            "summary": "Windows CSC Service Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00564,
            "epssPercentile": 0.4479,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21382",
            "title": "Windows Graphics Component Elevation of Privilege Vulnerability",
            "summary": "Windows Graphics Component Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00503,
            "epssPercentile": 0.41206,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21389",
            "title": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "summary": "Uncontrolled resource consumption in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0194,
            "epssPercentile": 0.78785,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21409",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21411",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21413",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21417",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01171,
            "epssPercentile": 0.6537,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-windows-kb5049983",
      "slug": "microsoft-2025-01-windows-kb5049983",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5049983",
      "title": "Deploy Microsoft Windows security update KB5049983",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5049983",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Windows Server 2022, Windows Server 2022 (Server Core installation)",
      "platform": "Windows",
      "release_version": "10.0.20348.3091",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21307",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows Server 2022, Windows Server 2022 (Server Core installation) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 120 linked CVEs for Windows Server 2022, Windows Server 2022 (Server Core installation). Microsoft marks CVE-2025-21275, CVE-2025-21308 as publicly disclosed, without that disclosure alone changing the BlackTree action window.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 120,
        "ids": [
          "CVE-2025-21189",
          "CVE-2025-21193",
          "CVE-2025-21202",
          "CVE-2025-21207",
          "CVE-2025-21210",
          "CVE-2025-21211",
          "CVE-2025-21213",
          "CVE-2025-21214",
          "CVE-2025-21215",
          "CVE-2025-21217",
          "CVE-2025-21218",
          "CVE-2025-21219",
          "CVE-2025-21220",
          "CVE-2025-21223",
          "CVE-2025-21224",
          "CVE-2025-21225",
          "CVE-2025-21226",
          "CVE-2025-21227",
          "CVE-2025-21228",
          "CVE-2025-21229",
          "CVE-2025-21230",
          "CVE-2025-21231",
          "CVE-2025-21232",
          "CVE-2025-21233",
          "CVE-2025-21234",
          "CVE-2025-21235",
          "CVE-2025-21236",
          "CVE-2025-21237",
          "CVE-2025-21238",
          "CVE-2025-21239",
          "CVE-2025-21240",
          "CVE-2025-21241",
          "CVE-2025-21242",
          "CVE-2025-21243",
          "CVE-2025-21244",
          "CVE-2025-21245",
          "CVE-2025-21246",
          "CVE-2025-21248",
          "CVE-2025-21249",
          "CVE-2025-21250",
          "CVE-2025-21251",
          "CVE-2025-21252",
          "CVE-2025-21255",
          "CVE-2025-21256",
          "CVE-2025-21257",
          "CVE-2025-21258",
          "CVE-2025-21260",
          "CVE-2025-21261",
          "CVE-2025-21263",
          "CVE-2025-21265",
          "CVE-2025-21266",
          "CVE-2025-21268",
          "CVE-2025-21269",
          "CVE-2025-21270",
          "CVE-2025-21271",
          "CVE-2025-21272",
          "CVE-2025-21273",
          "CVE-2025-21274",
          "CVE-2025-21275",
          "CVE-2025-21276",
          "CVE-2025-21277",
          "CVE-2025-21278",
          "CVE-2025-21280",
          "CVE-2025-21281",
          "CVE-2025-21282",
          "CVE-2025-21284",
          "CVE-2025-21285",
          "CVE-2025-21286",
          "CVE-2025-21287",
          "CVE-2025-21288",
          "CVE-2025-21289",
          "CVE-2025-21290",
          "CVE-2025-21291",
          "CVE-2025-21292",
          "CVE-2025-21293",
          "CVE-2025-21294",
          "CVE-2025-21295",
          "CVE-2025-21296",
          "CVE-2025-21297",
          "CVE-2025-21298",
          "CVE-2025-21299",
          "CVE-2025-21300",
          "CVE-2025-21301",
          "CVE-2025-21302",
          "CVE-2025-21303",
          "CVE-2025-21305",
          "CVE-2025-21306",
          "CVE-2025-21307",
          "CVE-2025-21308",
          "CVE-2025-21309",
          "CVE-2025-21310",
          "CVE-2025-21312",
          "CVE-2025-21314",
          "CVE-2025-21316",
          "CVE-2025-21317",
          "CVE-2025-21318",
          "CVE-2025-21319",
          "CVE-2025-21320",
          "CVE-2025-21321",
          "CVE-2025-21323",
          "CVE-2025-21324",
          "CVE-2025-21327",
          "CVE-2025-21328",
          "CVE-2025-21329",
          "CVE-2025-21330",
          "CVE-2025-21331",
          "CVE-2025-21332",
          "CVE-2025-21336",
          "CVE-2025-21338",
          "CVE-2025-21339",
          "CVE-2025-21340",
          "CVE-2025-21341",
          "CVE-2025-21374",
          "CVE-2025-21378",
          "CVE-2025-21382",
          "CVE-2025-21389",
          "CVE-2025-21409",
          "CVE-2025-21411",
          "CVE-2025-21413",
          "CVE-2025-21417"
        ],
        "details": [
          {
            "id": "CVE-2025-21189",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02971,
            "epssPercentile": 0.86348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21193",
            "title": "Active Directory Federation Server Spoofing Vulnerability",
            "summary": "Active Directory Federation Server Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00751,
            "epssPercentile": 0.5264,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21202",
            "title": "Windows Recovery Environment Agent Elevation of Privilege Vulnerability",
            "summary": "Windows Recovery Environment Agent Elevation of Privilege Vulnerability",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0088,
            "epssPercentile": 0.56753,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21207",
            "title": "Windows Connected Devices Platform Service (Cdpsvc) Denial of Service Vulnerability",
            "summary": "Windows Connected Devices Platform Service (Cdpsvc) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02108,
            "epssPercentile": 0.80554,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21210",
            "title": "Windows BitLocker Information Disclosure Vulnerability",
            "summary": "Windows BitLocker Information Disclosure Vulnerability",
            "score": 4.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01139,
            "epssPercentile": 0.64494,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21211",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Secure Boot Security Feature Bypass Vulnerability",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00773,
            "epssPercentile": 0.53349,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21213",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Secure Boot Security Feature Bypass Vulnerability",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0072,
            "epssPercentile": 0.51578,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21214",
            "title": "Windows BitLocker Information Disclosure Vulnerability",
            "summary": "Windows BitLocker Information Disclosure Vulnerability",
            "score": 4.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00713,
            "epssPercentile": 0.51333,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21215",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Secure Boot Security Feature Bypass Vulnerability",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00818,
            "epssPercentile": 0.5483,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21217",
            "title": "Windows NTLM Spoofing Vulnerability",
            "summary": "Windows NTLM Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01948,
            "epssPercentile": 0.78877,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21218",
            "title": "Windows Kerberos Denial of Service Vulnerability",
            "summary": "Windows Kerberos Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02589,
            "epssPercentile": 0.8425,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21219",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03017,
            "epssPercentile": 0.86549,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21220",
            "title": "Microsoft Message Queuing Information Disclosure Vulnerability",
            "summary": "Microsoft Message Queuing Information Disclosure Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02151,
            "epssPercentile": 0.80943,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21223",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01621,
            "epssPercentile": 0.74499,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21224",
            "title": "Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability",
            "summary": "Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01908,
            "epssPercentile": 0.78413,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21225",
            "title": "Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability",
            "summary": "Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01553,
            "epssPercentile": 0.73491,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21226",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00867,
            "epssPercentile": 0.5638,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21227",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21228",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21229",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21230",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02686,
            "epssPercentile": 0.84872,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21231",
            "title": "IP Helper Denial of Service Vulnerability",
            "summary": "IP Helper Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02591,
            "epssPercentile": 0.84283,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21232",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21233",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21234",
            "title": "Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability",
            "summary": "Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00598,
            "epssPercentile": 0.46439,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21235",
            "title": "Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability",
            "summary": "Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00596,
            "epssPercentile": 0.46331,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21236",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21237",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21238",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21239",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01489,
            "epssPercentile": 0.7238,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21240",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21241",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01489,
            "epssPercentile": 0.7238,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21242",
            "title": "Windows Kerberos Information Disclosure Vulnerability",
            "summary": "Windows Kerberos Information Disclosure Vulnerability",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01646,
            "epssPercentile": 0.74883,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21243",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21244",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21245",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21246",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21248",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01489,
            "epssPercentile": 0.72379,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21249",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21250",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21251",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02591,
            "epssPercentile": 0.84283,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21252",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21255",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21256",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21257",
            "title": "Windows WLAN AutoConfig Service Information Disclosure Vulnerability",
            "summary": "Windows WLAN AutoConfig Service Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00732,
            "epssPercentile": 0.51998,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21258",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21260",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55328,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21261",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21263",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21265",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21266",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21268",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01989,
            "epssPercentile": 0.79308,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21269",
            "title": "Windows HTML Platforms Security Feature Bypass Vulnerability",
            "summary": "Windows HTML Platforms Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.04593,
            "epssPercentile": 0.91034,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21270",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21271",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0054,
            "epssPercentile": 0.43498,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21272",
            "title": "Windows COM Server Information Disclosure Vulnerability",
            "summary": "Windows COM Server Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00706,
            "epssPercentile": 0.51085,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21273",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21274",
            "title": "Windows Event Tracing Denial of Service Vulnerability",
            "summary": "Windows Event Tracing Denial of Service Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00785,
            "epssPercentile": 0.53739,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21275",
            "title": "Windows App Package Installer Elevation of Privilege Vulnerability",
            "summary": "Windows App Package Installer Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00618,
            "epssPercentile": 0.47369,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21276",
            "title": "Windows MapUrlToZone Denial of Service Vulnerability",
            "summary": "Windows MapUrlToZone Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02421,
            "epssPercentile": 0.83098,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21277",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.38612,
            "epssPercentile": 0.98478,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21278",
            "title": "Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability",
            "summary": "Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0057,
            "epssPercentile": 0.45061,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21280",
            "title": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability",
            "summary": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49634,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21281",
            "title": "Microsoft COM for Windows Elevation of Privilege Vulnerability",
            "summary": "Microsoft COM for Windows Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00605,
            "epssPercentile": 0.46774,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21282",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21284",
            "title": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability",
            "summary": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49634,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21285",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.55686,
            "epssPercentile": 0.9897,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21286",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21287",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00549,
            "epssPercentile": 0.43984,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21288",
            "title": "Windows COM Server Information Disclosure Vulnerability",
            "summary": "Windows COM Server Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00706,
            "epssPercentile": 0.51085,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21289",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21290",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21291",
            "title": "Windows Direct Show Remote Code Execution Vulnerability",
            "summary": "Windows Direct Show Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01396,
            "epssPercentile": 0.70616,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21292",
            "title": "Windows Search Service Elevation of Privilege Vulnerability",
            "summary": "Windows Search Service Elevation of Privilege Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00825,
            "epssPercentile": 0.55027,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21293",
            "title": "Active Directory Domain Services Elevation of Privilege Vulnerability",
            "summary": "Active Directory Domain Services Elevation of Privilege Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.18825,
            "epssPercentile": 0.97091,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21294",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01209,
            "epssPercentile": 0.66385,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21295",
            "title": "SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability",
            "summary": "SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0161,
            "epssPercentile": 0.74316,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21296",
            "title": "BranchCache Remote Code Execution Vulnerability",
            "summary": "BranchCache Remote Code Execution Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00778,
            "epssPercentile": 0.53536,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21297",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01436,
            "epssPercentile": 0.71362,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21298",
            "title": "Windows OLE Remote Code Execution Vulnerability",
            "summary": "Windows OLE Remote Code Execution Vulnerability",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "CISA Vulnrichment records proof-of-concept exploitation in its SSVC data. BlackTree has not independently executed or validated exploit material.",
            "epss": 0.80912,
            "epssPercentile": 0.99602,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path and a public exploit reference; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21299",
            "title": "Windows Kerberos Security Feature Bypass Vulnerability",
            "summary": "Windows Kerberos Security Feature Bypass Vulnerability",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02212,
            "epssPercentile": 0.81462,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21300",
            "title": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "summary": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02531,
            "epssPercentile": 0.83874,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21301",
            "title": "Windows Geolocation Service Information Disclosure Vulnerability",
            "summary": "Windows Geolocation Service Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01564,
            "epssPercentile": 0.73648,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21302",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21303",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21305",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21306",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70986,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21307",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01909,
            "epssPercentile": 0.7842,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21308",
            "title": "Windows Themes Spoofing Vulnerability",
            "summary": "Windows Themes Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02208,
            "epssPercentile": 0.81432,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21309",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.14979,
            "epssPercentile": 0.96482,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21310",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21312",
            "title": "Windows Smart Card Reader Information Disclosure Vulnerability",
            "summary": "Windows Smart Card Reader Information Disclosure Vulnerability",
            "score": 2.4,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00718,
            "epssPercentile": 0.51518,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21314",
            "title": "Windows SmartScreen Spoofing Vulnerability",
            "summary": "Windows SmartScreen Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01421,
            "epssPercentile": 0.71094,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21316",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58304,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21317",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0085,
            "epssPercentile": 0.55808,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21318",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21319",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21320",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21321",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21323",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0085,
            "epssPercentile": 0.55807,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21324",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21327",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21328",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01518,
            "epssPercentile": 0.72882,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21329",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01518,
            "epssPercentile": 0.72882,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21330",
            "title": "Windows Remote Desktop Services Denial of Service Vulnerability",
            "summary": "Windows Remote Desktop Services Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01961,
            "epssPercentile": 0.79002,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21331",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01019,
            "epssPercentile": 0.61089,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21332",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01474,
            "epssPercentile": 0.72107,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21336",
            "title": "Windows Cryptographic Information Disclosure Vulnerability",
            "summary": "Windows Cryptographic Information Disclosure Vulnerability",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00631,
            "epssPercentile": 0.47982,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21338",
            "title": "GDI+ Remote Code Execution Vulnerability",
            "summary": "GDI+ Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39683,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21339",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21340",
            "title": "Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability",
            "summary": "Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00452,
            "epssPercentile": 0.37841,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21341",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00698,
            "epssPercentile": 0.50753,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21374",
            "title": "Windows CSC Service Information Disclosure Vulnerability",
            "summary": "Windows CSC Service Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00587,
            "epssPercentile": 0.45949,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21378",
            "title": "Windows CSC Service Elevation of Privilege Vulnerability",
            "summary": "Windows CSC Service Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00564,
            "epssPercentile": 0.4479,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21382",
            "title": "Windows Graphics Component Elevation of Privilege Vulnerability",
            "summary": "Windows Graphics Component Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00503,
            "epssPercentile": 0.41206,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21389",
            "title": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "summary": "Uncontrolled resource consumption in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0194,
            "epssPercentile": 0.78785,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21409",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21411",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21413",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21417",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01171,
            "epssPercentile": 0.6537,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-windows-kb5049984",
      "slug": "microsoft-2025-01-windows-kb5049984",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5049984",
      "title": "Deploy Microsoft Windows security update KB5049984",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5049984",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Windows Server 2022, 23H2 Edition (Server Core installation)",
      "platform": "Windows",
      "release_version": "10.0.25398.1369",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21311",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows Server 2022, 23H2 Edition (Server Core installation) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 126 linked CVEs for Windows Server 2022, 23H2 Edition (Server Core installation). Microsoft reports exploitation for CVE-2025-21333, CVE-2025-21334, CVE-2025-21335.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 126,
        "ids": [
          "CVE-2025-21189",
          "CVE-2025-21193",
          "CVE-2025-21202",
          "CVE-2025-21207",
          "CVE-2025-21210",
          "CVE-2025-21211",
          "CVE-2025-21213",
          "CVE-2025-21214",
          "CVE-2025-21215",
          "CVE-2025-21217",
          "CVE-2025-21218",
          "CVE-2025-21219",
          "CVE-2025-21220",
          "CVE-2025-21223",
          "CVE-2025-21224",
          "CVE-2025-21225",
          "CVE-2025-21226",
          "CVE-2025-21227",
          "CVE-2025-21228",
          "CVE-2025-21229",
          "CVE-2025-21230",
          "CVE-2025-21231",
          "CVE-2025-21232",
          "CVE-2025-21233",
          "CVE-2025-21234",
          "CVE-2025-21235",
          "CVE-2025-21236",
          "CVE-2025-21237",
          "CVE-2025-21238",
          "CVE-2025-21239",
          "CVE-2025-21240",
          "CVE-2025-21241",
          "CVE-2025-21242",
          "CVE-2025-21243",
          "CVE-2025-21244",
          "CVE-2025-21245",
          "CVE-2025-21246",
          "CVE-2025-21248",
          "CVE-2025-21249",
          "CVE-2025-21250",
          "CVE-2025-21251",
          "CVE-2025-21252",
          "CVE-2025-21255",
          "CVE-2025-21256",
          "CVE-2025-21257",
          "CVE-2025-21258",
          "CVE-2025-21260",
          "CVE-2025-21261",
          "CVE-2025-21263",
          "CVE-2025-21265",
          "CVE-2025-21266",
          "CVE-2025-21268",
          "CVE-2025-21269",
          "CVE-2025-21270",
          "CVE-2025-21272",
          "CVE-2025-21273",
          "CVE-2025-21274",
          "CVE-2025-21275",
          "CVE-2025-21276",
          "CVE-2025-21277",
          "CVE-2025-21278",
          "CVE-2025-21280",
          "CVE-2025-21281",
          "CVE-2025-21282",
          "CVE-2025-21284",
          "CVE-2025-21285",
          "CVE-2025-21286",
          "CVE-2025-21287",
          "CVE-2025-21288",
          "CVE-2025-21289",
          "CVE-2025-21290",
          "CVE-2025-21291",
          "CVE-2025-21292",
          "CVE-2025-21293",
          "CVE-2025-21294",
          "CVE-2025-21295",
          "CVE-2025-21296",
          "CVE-2025-21297",
          "CVE-2025-21298",
          "CVE-2025-21299",
          "CVE-2025-21300",
          "CVE-2025-21301",
          "CVE-2025-21302",
          "CVE-2025-21303",
          "CVE-2025-21305",
          "CVE-2025-21306",
          "CVE-2025-21307",
          "CVE-2025-21309",
          "CVE-2025-21310",
          "CVE-2025-21311",
          "CVE-2025-21312",
          "CVE-2025-21313",
          "CVE-2025-21314",
          "CVE-2025-21315",
          "CVE-2025-21316",
          "CVE-2025-21317",
          "CVE-2025-21318",
          "CVE-2025-21319",
          "CVE-2025-21320",
          "CVE-2025-21321",
          "CVE-2025-21323",
          "CVE-2025-21324",
          "CVE-2025-21326",
          "CVE-2025-21327",
          "CVE-2025-21328",
          "CVE-2025-21329",
          "CVE-2025-21330",
          "CVE-2025-21331",
          "CVE-2025-21332",
          "CVE-2025-21333",
          "CVE-2025-21334",
          "CVE-2025-21335",
          "CVE-2025-21336",
          "CVE-2025-21338",
          "CVE-2025-21339",
          "CVE-2025-21340",
          "CVE-2025-21341",
          "CVE-2025-21372",
          "CVE-2025-21374",
          "CVE-2025-21378",
          "CVE-2025-21382",
          "CVE-2025-21389",
          "CVE-2025-21409",
          "CVE-2025-21411",
          "CVE-2025-21413",
          "CVE-2025-21417"
        ],
        "details": [
          {
            "id": "CVE-2025-21189",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02971,
            "epssPercentile": 0.86348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21193",
            "title": "Active Directory Federation Server Spoofing Vulnerability",
            "summary": "Active Directory Federation Server Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00751,
            "epssPercentile": 0.5264,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21202",
            "title": "Windows Recovery Environment Agent Elevation of Privilege Vulnerability",
            "summary": "Windows Recovery Environment Agent Elevation of Privilege Vulnerability",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0088,
            "epssPercentile": 0.56753,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21207",
            "title": "Windows Connected Devices Platform Service (Cdpsvc) Denial of Service Vulnerability",
            "summary": "Windows Connected Devices Platform Service (Cdpsvc) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02108,
            "epssPercentile": 0.80554,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21210",
            "title": "Windows BitLocker Information Disclosure Vulnerability",
            "summary": "Windows BitLocker Information Disclosure Vulnerability",
            "score": 4.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01139,
            "epssPercentile": 0.64494,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21211",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Secure Boot Security Feature Bypass Vulnerability",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00773,
            "epssPercentile": 0.53349,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21213",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Secure Boot Security Feature Bypass Vulnerability",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0072,
            "epssPercentile": 0.51578,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21214",
            "title": "Windows BitLocker Information Disclosure Vulnerability",
            "summary": "Windows BitLocker Information Disclosure Vulnerability",
            "score": 4.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00713,
            "epssPercentile": 0.51333,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21215",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Secure Boot Security Feature Bypass Vulnerability",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00818,
            "epssPercentile": 0.5483,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21217",
            "title": "Windows NTLM Spoofing Vulnerability",
            "summary": "Windows NTLM Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01948,
            "epssPercentile": 0.78877,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21218",
            "title": "Windows Kerberos Denial of Service Vulnerability",
            "summary": "Windows Kerberos Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02589,
            "epssPercentile": 0.8425,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21219",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03017,
            "epssPercentile": 0.86549,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21220",
            "title": "Microsoft Message Queuing Information Disclosure Vulnerability",
            "summary": "Microsoft Message Queuing Information Disclosure Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02151,
            "epssPercentile": 0.80943,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21223",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01621,
            "epssPercentile": 0.74499,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21224",
            "title": "Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability",
            "summary": "Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01908,
            "epssPercentile": 0.78413,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21225",
            "title": "Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability",
            "summary": "Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01553,
            "epssPercentile": 0.73491,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21226",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00867,
            "epssPercentile": 0.5638,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21227",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21228",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21229",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21230",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02686,
            "epssPercentile": 0.84872,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21231",
            "title": "IP Helper Denial of Service Vulnerability",
            "summary": "IP Helper Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02591,
            "epssPercentile": 0.84283,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21232",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21233",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21234",
            "title": "Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability",
            "summary": "Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00598,
            "epssPercentile": 0.46439,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21235",
            "title": "Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability",
            "summary": "Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00596,
            "epssPercentile": 0.46331,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21236",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21237",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21238",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21239",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01489,
            "epssPercentile": 0.7238,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21240",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21241",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01489,
            "epssPercentile": 0.7238,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21242",
            "title": "Windows Kerberos Information Disclosure Vulnerability",
            "summary": "Windows Kerberos Information Disclosure Vulnerability",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01646,
            "epssPercentile": 0.74883,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21243",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21244",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21245",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21246",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21248",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01489,
            "epssPercentile": 0.72379,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21249",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21250",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21251",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02591,
            "epssPercentile": 0.84283,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21252",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21255",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21256",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21257",
            "title": "Windows WLAN AutoConfig Service Information Disclosure Vulnerability",
            "summary": "Windows WLAN AutoConfig Service Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00732,
            "epssPercentile": 0.51998,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21258",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21260",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55328,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21261",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21263",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21265",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21266",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21268",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01989,
            "epssPercentile": 0.79308,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21269",
            "title": "Windows HTML Platforms Security Feature Bypass Vulnerability",
            "summary": "Windows HTML Platforms Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.04593,
            "epssPercentile": 0.91034,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21270",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21272",
            "title": "Windows COM Server Information Disclosure Vulnerability",
            "summary": "Windows COM Server Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00706,
            "epssPercentile": 0.51085,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21273",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21274",
            "title": "Windows Event Tracing Denial of Service Vulnerability",
            "summary": "Windows Event Tracing Denial of Service Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00785,
            "epssPercentile": 0.53739,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21275",
            "title": "Windows App Package Installer Elevation of Privilege Vulnerability",
            "summary": "Windows App Package Installer Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00618,
            "epssPercentile": 0.47369,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21276",
            "title": "Windows MapUrlToZone Denial of Service Vulnerability",
            "summary": "Windows MapUrlToZone Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02421,
            "epssPercentile": 0.83098,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21277",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.38612,
            "epssPercentile": 0.98478,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21278",
            "title": "Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability",
            "summary": "Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0057,
            "epssPercentile": 0.45061,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21280",
            "title": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability",
            "summary": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49634,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21281",
            "title": "Microsoft COM for Windows Elevation of Privilege Vulnerability",
            "summary": "Microsoft COM for Windows Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00605,
            "epssPercentile": 0.46774,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21282",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21284",
            "title": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability",
            "summary": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49634,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21285",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.55686,
            "epssPercentile": 0.9897,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21286",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21287",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00549,
            "epssPercentile": 0.43984,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21288",
            "title": "Windows COM Server Information Disclosure Vulnerability",
            "summary": "Windows COM Server Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00706,
            "epssPercentile": 0.51085,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21289",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21290",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21291",
            "title": "Windows Direct Show Remote Code Execution Vulnerability",
            "summary": "Windows Direct Show Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01396,
            "epssPercentile": 0.70616,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21292",
            "title": "Windows Search Service Elevation of Privilege Vulnerability",
            "summary": "Windows Search Service Elevation of Privilege Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00825,
            "epssPercentile": 0.55027,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21293",
            "title": "Active Directory Domain Services Elevation of Privilege Vulnerability",
            "summary": "Active Directory Domain Services Elevation of Privilege Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.18825,
            "epssPercentile": 0.97091,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21294",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01209,
            "epssPercentile": 0.66385,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21295",
            "title": "SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability",
            "summary": "SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0161,
            "epssPercentile": 0.74316,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21296",
            "title": "BranchCache Remote Code Execution Vulnerability",
            "summary": "BranchCache Remote Code Execution Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00778,
            "epssPercentile": 0.53536,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21297",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01436,
            "epssPercentile": 0.71362,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21298",
            "title": "Windows OLE Remote Code Execution Vulnerability",
            "summary": "Windows OLE Remote Code Execution Vulnerability",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "CISA Vulnrichment records proof-of-concept exploitation in its SSVC data. BlackTree has not independently executed or validated exploit material.",
            "epss": 0.80912,
            "epssPercentile": 0.99602,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path and a public exploit reference; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21299",
            "title": "Windows Kerberos Security Feature Bypass Vulnerability",
            "summary": "Windows Kerberos Security Feature Bypass Vulnerability",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02212,
            "epssPercentile": 0.81462,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21300",
            "title": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "summary": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02531,
            "epssPercentile": 0.83874,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21301",
            "title": "Windows Geolocation Service Information Disclosure Vulnerability",
            "summary": "Windows Geolocation Service Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01564,
            "epssPercentile": 0.73648,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21302",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21303",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21305",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21306",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70986,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21307",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01909,
            "epssPercentile": 0.7842,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21309",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.14979,
            "epssPercentile": 0.96482,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21310",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21311",
            "title": "Windows NTLM V1 Elevation of Privilege Vulnerability",
            "summary": "Windows NTLM V1 Elevation of Privilege Vulnerability",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0223,
            "epssPercentile": 0.8161,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21312",
            "title": "Windows Smart Card Reader Information Disclosure Vulnerability",
            "summary": "Windows Smart Card Reader Information Disclosure Vulnerability",
            "score": 2.4,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00718,
            "epssPercentile": 0.51518,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21313",
            "title": "Windows Security Account Manager (SAM) Denial of Service Vulnerability",
            "summary": "Windows Security Account Manager (SAM) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01633,
            "epssPercentile": 0.74684,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21314",
            "title": "Windows SmartScreen Spoofing Vulnerability",
            "summary": "Windows SmartScreen Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01421,
            "epssPercentile": 0.71094,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21315",
            "title": "Microsoft Brokering File System Elevation of Privilege Vulnerability",
            "summary": "Microsoft Brokering File System Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00641,
            "epssPercentile": 0.48461,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21316",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58304,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21317",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0085,
            "epssPercentile": 0.55808,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21318",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21319",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21320",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21321",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21323",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0085,
            "epssPercentile": 0.55807,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21324",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21326",
            "title": "Internet Explorer Remote Code Execution Vulnerability",
            "summary": "Internet Explorer Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01316,
            "epssPercentile": 0.68883,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21327",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21328",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01518,
            "epssPercentile": 0.72882,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21329",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01518,
            "epssPercentile": 0.72882,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21330",
            "title": "Windows Remote Desktop Services Denial of Service Vulnerability",
            "summary": "Windows Remote Desktop Services Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01961,
            "epssPercentile": 0.79002,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21331",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01019,
            "epssPercentile": 0.61089,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21332",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01474,
            "epssPercentile": 0.72107,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21333",
            "title": "Microsoft Windows Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows Hyper-V NT Kernel Integration VSP contains a heap-based buffer overflow vulnerability that allows a local attacker to gain SYSTEM privileges.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-01-14.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.09988,
            "epssPercentile": 0.95287,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-02-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21334",
            "title": "Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability",
            "summary": "Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-01-14.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01561,
            "epssPercentile": 0.73599,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-02-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21335",
            "title": "Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability",
            "summary": "Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-01-14.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0139,
            "epssPercentile": 0.70518,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-02-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21336",
            "title": "Windows Cryptographic Information Disclosure Vulnerability",
            "summary": "Windows Cryptographic Information Disclosure Vulnerability",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00631,
            "epssPercentile": 0.47982,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21338",
            "title": "GDI+ Remote Code Execution Vulnerability",
            "summary": "GDI+ Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39683,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21339",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21340",
            "title": "Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability",
            "summary": "Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00452,
            "epssPercentile": 0.37841,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21341",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00698,
            "epssPercentile": 0.50753,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21372",
            "title": "Microsoft Brokering File System Elevation of Privilege Vulnerability",
            "summary": "Microsoft Brokering File System Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00398,
            "epssPercentile": 0.33078,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21374",
            "title": "Windows CSC Service Information Disclosure Vulnerability",
            "summary": "Windows CSC Service Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00587,
            "epssPercentile": 0.45949,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21378",
            "title": "Windows CSC Service Elevation of Privilege Vulnerability",
            "summary": "Windows CSC Service Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00564,
            "epssPercentile": 0.4479,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21382",
            "title": "Windows Graphics Component Elevation of Privilege Vulnerability",
            "summary": "Windows Graphics Component Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00503,
            "epssPercentile": 0.41206,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21389",
            "title": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "summary": "Uncontrolled resource consumption in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0194,
            "epssPercentile": 0.78785,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21409",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21411",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21413",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21417",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01171,
            "epssPercentile": 0.6537,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-windows-kb5049993",
      "slug": "microsoft-2025-01-windows-kb5049993",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5049993",
      "title": "Deploy Microsoft Windows security update KB5049993",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5049993",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Windows 10 Version 1607 for 32-bit Systems, Windows 10 Version 1607 for x64-based Systems, Windows Server 2016, plus 1 more",
      "platform": "Windows",
      "release_version": "10.0.14393.7699",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21307",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows 10 Version 1607 for 32-bit Systems, Windows 10 Version 1607 for x64-based Systems, Windows Server 2016, plus 1 more exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 109 linked CVEs for Windows 10 Version 1607 for 32-bit Systems, Windows 10 Version 1607 for x64-based Systems, Windows Server 2016, plus 1 more. Microsoft marks CVE-2025-21308 as publicly disclosed, without that disclosure alone changing the BlackTree action window.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 109,
        "ids": [
          "CVE-2025-21189",
          "CVE-2025-21193",
          "CVE-2025-21202",
          "CVE-2025-21210",
          "CVE-2025-21211",
          "CVE-2025-21213",
          "CVE-2025-21214",
          "CVE-2025-21215",
          "CVE-2025-21217",
          "CVE-2025-21218",
          "CVE-2025-21219",
          "CVE-2025-21220",
          "CVE-2025-21223",
          "CVE-2025-21225",
          "CVE-2025-21226",
          "CVE-2025-21227",
          "CVE-2025-21228",
          "CVE-2025-21229",
          "CVE-2025-21230",
          "CVE-2025-21231",
          "CVE-2025-21232",
          "CVE-2025-21233",
          "CVE-2025-21236",
          "CVE-2025-21237",
          "CVE-2025-21238",
          "CVE-2025-21239",
          "CVE-2025-21240",
          "CVE-2025-21241",
          "CVE-2025-21242",
          "CVE-2025-21243",
          "CVE-2025-21244",
          "CVE-2025-21245",
          "CVE-2025-21246",
          "CVE-2025-21248",
          "CVE-2025-21249",
          "CVE-2025-21250",
          "CVE-2025-21251",
          "CVE-2025-21252",
          "CVE-2025-21255",
          "CVE-2025-21256",
          "CVE-2025-21257",
          "CVE-2025-21258",
          "CVE-2025-21260",
          "CVE-2025-21261",
          "CVE-2025-21263",
          "CVE-2025-21265",
          "CVE-2025-21266",
          "CVE-2025-21268",
          "CVE-2025-21269",
          "CVE-2025-21270",
          "CVE-2025-21272",
          "CVE-2025-21273",
          "CVE-2025-21274",
          "CVE-2025-21276",
          "CVE-2025-21277",
          "CVE-2025-21278",
          "CVE-2025-21280",
          "CVE-2025-21281",
          "CVE-2025-21282",
          "CVE-2025-21284",
          "CVE-2025-21285",
          "CVE-2025-21286",
          "CVE-2025-21287",
          "CVE-2025-21288",
          "CVE-2025-21289",
          "CVE-2025-21290",
          "CVE-2025-21293",
          "CVE-2025-21294",
          "CVE-2025-21295",
          "CVE-2025-21296",
          "CVE-2025-21297",
          "CVE-2025-21298",
          "CVE-2025-21299",
          "CVE-2025-21300",
          "CVE-2025-21301",
          "CVE-2025-21302",
          "CVE-2025-21303",
          "CVE-2025-21304",
          "CVE-2025-21305",
          "CVE-2025-21306",
          "CVE-2025-21307",
          "CVE-2025-21308",
          "CVE-2025-21309",
          "CVE-2025-21310",
          "CVE-2025-21312",
          "CVE-2025-21314",
          "CVE-2025-21316",
          "CVE-2025-21318",
          "CVE-2025-21319",
          "CVE-2025-21320",
          "CVE-2025-21321",
          "CVE-2025-21323",
          "CVE-2025-21324",
          "CVE-2025-21327",
          "CVE-2025-21328",
          "CVE-2025-21329",
          "CVE-2025-21331",
          "CVE-2025-21332",
          "CVE-2025-21336",
          "CVE-2025-21338",
          "CVE-2025-21339",
          "CVE-2025-21341",
          "CVE-2025-21374",
          "CVE-2025-21378",
          "CVE-2025-21389",
          "CVE-2025-21409",
          "CVE-2025-21411",
          "CVE-2025-21413",
          "CVE-2025-21417"
        ],
        "details": [
          {
            "id": "CVE-2025-21189",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02971,
            "epssPercentile": 0.86348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21193",
            "title": "Active Directory Federation Server Spoofing Vulnerability",
            "summary": "Active Directory Federation Server Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00751,
            "epssPercentile": 0.5264,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21202",
            "title": "Windows Recovery Environment Agent Elevation of Privilege Vulnerability",
            "summary": "Windows Recovery Environment Agent Elevation of Privilege Vulnerability",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0088,
            "epssPercentile": 0.56753,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21210",
            "title": "Windows BitLocker Information Disclosure Vulnerability",
            "summary": "Windows BitLocker Information Disclosure Vulnerability",
            "score": 4.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01139,
            "epssPercentile": 0.64494,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21211",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Secure Boot Security Feature Bypass Vulnerability",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00773,
            "epssPercentile": 0.53349,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21213",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Secure Boot Security Feature Bypass Vulnerability",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0072,
            "epssPercentile": 0.51578,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21214",
            "title": "Windows BitLocker Information Disclosure Vulnerability",
            "summary": "Windows BitLocker Information Disclosure Vulnerability",
            "score": 4.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00713,
            "epssPercentile": 0.51333,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21215",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Secure Boot Security Feature Bypass Vulnerability",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00818,
            "epssPercentile": 0.5483,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21217",
            "title": "Windows NTLM Spoofing Vulnerability",
            "summary": "Windows NTLM Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01948,
            "epssPercentile": 0.78877,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21218",
            "title": "Windows Kerberos Denial of Service Vulnerability",
            "summary": "Windows Kerberos Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02589,
            "epssPercentile": 0.8425,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21219",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03017,
            "epssPercentile": 0.86549,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21220",
            "title": "Microsoft Message Queuing Information Disclosure Vulnerability",
            "summary": "Microsoft Message Queuing Information Disclosure Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02151,
            "epssPercentile": 0.80943,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21223",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01621,
            "epssPercentile": 0.74499,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21225",
            "title": "Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability",
            "summary": "Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01553,
            "epssPercentile": 0.73491,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21226",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00867,
            "epssPercentile": 0.5638,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21227",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21228",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21229",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21230",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02686,
            "epssPercentile": 0.84872,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21231",
            "title": "IP Helper Denial of Service Vulnerability",
            "summary": "IP Helper Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02591,
            "epssPercentile": 0.84283,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21232",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21233",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21236",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21237",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21238",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21239",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01489,
            "epssPercentile": 0.7238,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21240",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21241",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01489,
            "epssPercentile": 0.7238,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21242",
            "title": "Windows Kerberos Information Disclosure Vulnerability",
            "summary": "Windows Kerberos Information Disclosure Vulnerability",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01646,
            "epssPercentile": 0.74883,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21243",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21244",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21245",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21246",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21248",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01489,
            "epssPercentile": 0.72379,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21249",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21250",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21251",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02591,
            "epssPercentile": 0.84283,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21252",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21255",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21256",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21257",
            "title": "Windows WLAN AutoConfig Service Information Disclosure Vulnerability",
            "summary": "Windows WLAN AutoConfig Service Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00732,
            "epssPercentile": 0.51998,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21258",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21260",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55328,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21261",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21263",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21265",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21266",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21268",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01989,
            "epssPercentile": 0.79308,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21269",
            "title": "Windows HTML Platforms Security Feature Bypass Vulnerability",
            "summary": "Windows HTML Platforms Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.04593,
            "epssPercentile": 0.91034,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21270",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21272",
            "title": "Windows COM Server Information Disclosure Vulnerability",
            "summary": "Windows COM Server Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00706,
            "epssPercentile": 0.51085,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21273",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21274",
            "title": "Windows Event Tracing Denial of Service Vulnerability",
            "summary": "Windows Event Tracing Denial of Service Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00785,
            "epssPercentile": 0.53739,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21276",
            "title": "Windows MapUrlToZone Denial of Service Vulnerability",
            "summary": "Windows MapUrlToZone Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02421,
            "epssPercentile": 0.83098,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21277",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.38612,
            "epssPercentile": 0.98478,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21278",
            "title": "Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability",
            "summary": "Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0057,
            "epssPercentile": 0.45061,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21280",
            "title": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability",
            "summary": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49634,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21281",
            "title": "Microsoft COM for Windows Elevation of Privilege Vulnerability",
            "summary": "Microsoft COM for Windows Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00605,
            "epssPercentile": 0.46774,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21282",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21284",
            "title": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability",
            "summary": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49634,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21285",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.55686,
            "epssPercentile": 0.9897,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21286",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21287",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00549,
            "epssPercentile": 0.43984,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21288",
            "title": "Windows COM Server Information Disclosure Vulnerability",
            "summary": "Windows COM Server Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00706,
            "epssPercentile": 0.51085,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21289",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21290",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21293",
            "title": "Active Directory Domain Services Elevation of Privilege Vulnerability",
            "summary": "Active Directory Domain Services Elevation of Privilege Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.18825,
            "epssPercentile": 0.97091,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21294",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01209,
            "epssPercentile": 0.66385,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21295",
            "title": "SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability",
            "summary": "SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0161,
            "epssPercentile": 0.74316,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21296",
            "title": "BranchCache Remote Code Execution Vulnerability",
            "summary": "BranchCache Remote Code Execution Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00778,
            "epssPercentile": 0.53536,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21297",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01436,
            "epssPercentile": 0.71362,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21298",
            "title": "Windows OLE Remote Code Execution Vulnerability",
            "summary": "Windows OLE Remote Code Execution Vulnerability",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "CISA Vulnrichment records proof-of-concept exploitation in its SSVC data. BlackTree has not independently executed or validated exploit material.",
            "epss": 0.80912,
            "epssPercentile": 0.99602,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path and a public exploit reference; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21299",
            "title": "Windows Kerberos Security Feature Bypass Vulnerability",
            "summary": "Windows Kerberos Security Feature Bypass Vulnerability",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02212,
            "epssPercentile": 0.81462,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21300",
            "title": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "summary": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02531,
            "epssPercentile": 0.83874,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21301",
            "title": "Windows Geolocation Service Information Disclosure Vulnerability",
            "summary": "Windows Geolocation Service Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01564,
            "epssPercentile": 0.73648,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21302",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21303",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21304",
            "title": "Microsoft DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Microsoft DWM Core Library Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00604,
            "epssPercentile": 0.46711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21305",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21306",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70986,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21307",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01909,
            "epssPercentile": 0.7842,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21308",
            "title": "Windows Themes Spoofing Vulnerability",
            "summary": "Windows Themes Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02208,
            "epssPercentile": 0.81432,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21309",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.14979,
            "epssPercentile": 0.96482,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21310",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21312",
            "title": "Windows Smart Card Reader Information Disclosure Vulnerability",
            "summary": "Windows Smart Card Reader Information Disclosure Vulnerability",
            "score": 2.4,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00718,
            "epssPercentile": 0.51518,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21314",
            "title": "Windows SmartScreen Spoofing Vulnerability",
            "summary": "Windows SmartScreen Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01421,
            "epssPercentile": 0.71094,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21316",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58304,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21318",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21319",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21320",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21321",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21323",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0085,
            "epssPercentile": 0.55807,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21324",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21327",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21328",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01518,
            "epssPercentile": 0.72882,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21329",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01518,
            "epssPercentile": 0.72882,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21331",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01019,
            "epssPercentile": 0.61089,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21332",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01474,
            "epssPercentile": 0.72107,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21336",
            "title": "Windows Cryptographic Information Disclosure Vulnerability",
            "summary": "Windows Cryptographic Information Disclosure Vulnerability",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00631,
            "epssPercentile": 0.47982,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21338",
            "title": "GDI+ Remote Code Execution Vulnerability",
            "summary": "GDI+ Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39683,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21339",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21341",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00698,
            "epssPercentile": 0.50753,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21374",
            "title": "Windows CSC Service Information Disclosure Vulnerability",
            "summary": "Windows CSC Service Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00587,
            "epssPercentile": 0.45949,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21378",
            "title": "Windows CSC Service Elevation of Privilege Vulnerability",
            "summary": "Windows CSC Service Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00564,
            "epssPercentile": 0.4479,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21389",
            "title": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "summary": "Uncontrolled resource consumption in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0194,
            "epssPercentile": 0.78785,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21409",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21411",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21413",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21417",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01171,
            "epssPercentile": 0.6537,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-windows-kb5050008",
      "slug": "microsoft-2025-01-windows-kb5050008",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5050008",
      "title": "Deploy Microsoft Windows security update KB5050008",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5050008",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, plus 1 more",
      "platform": "Windows",
      "release_version": "10.0.17763.6775",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21307",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, plus 1 more exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 116 linked CVEs for Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, plus 1 more. Microsoft marks CVE-2025-21308 as publicly disclosed, without that disclosure alone changing the BlackTree action window.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 116,
        "ids": [
          "CVE-2025-21189",
          "CVE-2025-21193",
          "CVE-2025-21202",
          "CVE-2025-21207",
          "CVE-2025-21210",
          "CVE-2025-21211",
          "CVE-2025-21213",
          "CVE-2025-21214",
          "CVE-2025-21215",
          "CVE-2025-21217",
          "CVE-2025-21218",
          "CVE-2025-21219",
          "CVE-2025-21220",
          "CVE-2025-21223",
          "CVE-2025-21225",
          "CVE-2025-21226",
          "CVE-2025-21227",
          "CVE-2025-21228",
          "CVE-2025-21229",
          "CVE-2025-21230",
          "CVE-2025-21231",
          "CVE-2025-21232",
          "CVE-2025-21233",
          "CVE-2025-21236",
          "CVE-2025-21237",
          "CVE-2025-21238",
          "CVE-2025-21239",
          "CVE-2025-21240",
          "CVE-2025-21241",
          "CVE-2025-21242",
          "CVE-2025-21243",
          "CVE-2025-21244",
          "CVE-2025-21245",
          "CVE-2025-21246",
          "CVE-2025-21248",
          "CVE-2025-21249",
          "CVE-2025-21250",
          "CVE-2025-21251",
          "CVE-2025-21252",
          "CVE-2025-21255",
          "CVE-2025-21256",
          "CVE-2025-21257",
          "CVE-2025-21258",
          "CVE-2025-21260",
          "CVE-2025-21261",
          "CVE-2025-21263",
          "CVE-2025-21265",
          "CVE-2025-21266",
          "CVE-2025-21268",
          "CVE-2025-21269",
          "CVE-2025-21270",
          "CVE-2025-21271",
          "CVE-2025-21272",
          "CVE-2025-21273",
          "CVE-2025-21274",
          "CVE-2025-21276",
          "CVE-2025-21277",
          "CVE-2025-21278",
          "CVE-2025-21280",
          "CVE-2025-21281",
          "CVE-2025-21282",
          "CVE-2025-21284",
          "CVE-2025-21285",
          "CVE-2025-21286",
          "CVE-2025-21287",
          "CVE-2025-21288",
          "CVE-2025-21289",
          "CVE-2025-21290",
          "CVE-2025-21291",
          "CVE-2025-21292",
          "CVE-2025-21293",
          "CVE-2025-21294",
          "CVE-2025-21295",
          "CVE-2025-21296",
          "CVE-2025-21297",
          "CVE-2025-21298",
          "CVE-2025-21299",
          "CVE-2025-21300",
          "CVE-2025-21301",
          "CVE-2025-21302",
          "CVE-2025-21303",
          "CVE-2025-21304",
          "CVE-2025-21305",
          "CVE-2025-21306",
          "CVE-2025-21307",
          "CVE-2025-21308",
          "CVE-2025-21309",
          "CVE-2025-21310",
          "CVE-2025-21312",
          "CVE-2025-21314",
          "CVE-2025-21316",
          "CVE-2025-21318",
          "CVE-2025-21319",
          "CVE-2025-21320",
          "CVE-2025-21321",
          "CVE-2025-21323",
          "CVE-2025-21324",
          "CVE-2025-21327",
          "CVE-2025-21328",
          "CVE-2025-21329",
          "CVE-2025-21330",
          "CVE-2025-21331",
          "CVE-2025-21332",
          "CVE-2025-21336",
          "CVE-2025-21338",
          "CVE-2025-21339",
          "CVE-2025-21340",
          "CVE-2025-21341",
          "CVE-2025-21374",
          "CVE-2025-21378",
          "CVE-2025-21382",
          "CVE-2025-21389",
          "CVE-2025-21409",
          "CVE-2025-21411",
          "CVE-2025-21413",
          "CVE-2025-21417"
        ],
        "details": [
          {
            "id": "CVE-2025-21189",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02971,
            "epssPercentile": 0.86348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21193",
            "title": "Active Directory Federation Server Spoofing Vulnerability",
            "summary": "Active Directory Federation Server Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00751,
            "epssPercentile": 0.5264,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21202",
            "title": "Windows Recovery Environment Agent Elevation of Privilege Vulnerability",
            "summary": "Windows Recovery Environment Agent Elevation of Privilege Vulnerability",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0088,
            "epssPercentile": 0.56753,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21207",
            "title": "Windows Connected Devices Platform Service (Cdpsvc) Denial of Service Vulnerability",
            "summary": "Windows Connected Devices Platform Service (Cdpsvc) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02108,
            "epssPercentile": 0.80554,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21210",
            "title": "Windows BitLocker Information Disclosure Vulnerability",
            "summary": "Windows BitLocker Information Disclosure Vulnerability",
            "score": 4.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01139,
            "epssPercentile": 0.64494,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21211",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Secure Boot Security Feature Bypass Vulnerability",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00773,
            "epssPercentile": 0.53349,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21213",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Secure Boot Security Feature Bypass Vulnerability",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0072,
            "epssPercentile": 0.51578,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21214",
            "title": "Windows BitLocker Information Disclosure Vulnerability",
            "summary": "Windows BitLocker Information Disclosure Vulnerability",
            "score": 4.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00713,
            "epssPercentile": 0.51333,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21215",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Secure Boot Security Feature Bypass Vulnerability",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00818,
            "epssPercentile": 0.5483,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21217",
            "title": "Windows NTLM Spoofing Vulnerability",
            "summary": "Windows NTLM Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01948,
            "epssPercentile": 0.78877,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21218",
            "title": "Windows Kerberos Denial of Service Vulnerability",
            "summary": "Windows Kerberos Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02589,
            "epssPercentile": 0.8425,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21219",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03017,
            "epssPercentile": 0.86549,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21220",
            "title": "Microsoft Message Queuing Information Disclosure Vulnerability",
            "summary": "Microsoft Message Queuing Information Disclosure Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02151,
            "epssPercentile": 0.80943,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21223",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01621,
            "epssPercentile": 0.74499,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21225",
            "title": "Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability",
            "summary": "Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01553,
            "epssPercentile": 0.73491,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21226",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00867,
            "epssPercentile": 0.5638,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21227",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21228",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21229",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21230",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02686,
            "epssPercentile": 0.84872,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21231",
            "title": "IP Helper Denial of Service Vulnerability",
            "summary": "IP Helper Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02591,
            "epssPercentile": 0.84283,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21232",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21233",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21236",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21237",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21238",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21239",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01489,
            "epssPercentile": 0.7238,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21240",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21241",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01489,
            "epssPercentile": 0.7238,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21242",
            "title": "Windows Kerberos Information Disclosure Vulnerability",
            "summary": "Windows Kerberos Information Disclosure Vulnerability",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01646,
            "epssPercentile": 0.74883,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21243",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21244",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21245",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21246",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21248",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01489,
            "epssPercentile": 0.72379,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21249",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21250",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21251",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02591,
            "epssPercentile": 0.84283,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21252",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21255",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21256",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21257",
            "title": "Windows WLAN AutoConfig Service Information Disclosure Vulnerability",
            "summary": "Windows WLAN AutoConfig Service Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00732,
            "epssPercentile": 0.51998,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21258",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21260",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55328,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21261",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21263",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21265",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21266",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21268",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01989,
            "epssPercentile": 0.79308,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21269",
            "title": "Windows HTML Platforms Security Feature Bypass Vulnerability",
            "summary": "Windows HTML Platforms Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.04593,
            "epssPercentile": 0.91034,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21270",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21271",
            "title": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "summary": "Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0054,
            "epssPercentile": 0.43498,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21272",
            "title": "Windows COM Server Information Disclosure Vulnerability",
            "summary": "Windows COM Server Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00706,
            "epssPercentile": 0.51085,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21273",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21274",
            "title": "Windows Event Tracing Denial of Service Vulnerability",
            "summary": "Windows Event Tracing Denial of Service Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00785,
            "epssPercentile": 0.53739,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21276",
            "title": "Windows MapUrlToZone Denial of Service Vulnerability",
            "summary": "Windows MapUrlToZone Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02421,
            "epssPercentile": 0.83098,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21277",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.38612,
            "epssPercentile": 0.98478,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21278",
            "title": "Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability",
            "summary": "Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0057,
            "epssPercentile": 0.45061,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21280",
            "title": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability",
            "summary": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49634,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21281",
            "title": "Microsoft COM for Windows Elevation of Privilege Vulnerability",
            "summary": "Microsoft COM for Windows Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00605,
            "epssPercentile": 0.46774,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21282",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21284",
            "title": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability",
            "summary": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49634,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21285",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.55686,
            "epssPercentile": 0.9897,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21286",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21287",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00549,
            "epssPercentile": 0.43984,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21288",
            "title": "Windows COM Server Information Disclosure Vulnerability",
            "summary": "Windows COM Server Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00706,
            "epssPercentile": 0.51085,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21289",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21290",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21291",
            "title": "Windows Direct Show Remote Code Execution Vulnerability",
            "summary": "Windows Direct Show Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01396,
            "epssPercentile": 0.70616,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21292",
            "title": "Windows Search Service Elevation of Privilege Vulnerability",
            "summary": "Windows Search Service Elevation of Privilege Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00825,
            "epssPercentile": 0.55027,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21293",
            "title": "Active Directory Domain Services Elevation of Privilege Vulnerability",
            "summary": "Active Directory Domain Services Elevation of Privilege Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.18825,
            "epssPercentile": 0.97091,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21294",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01209,
            "epssPercentile": 0.66385,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21295",
            "title": "SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability",
            "summary": "SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0161,
            "epssPercentile": 0.74316,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21296",
            "title": "BranchCache Remote Code Execution Vulnerability",
            "summary": "BranchCache Remote Code Execution Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00778,
            "epssPercentile": 0.53536,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21297",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01436,
            "epssPercentile": 0.71362,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21298",
            "title": "Windows OLE Remote Code Execution Vulnerability",
            "summary": "Windows OLE Remote Code Execution Vulnerability",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "CISA Vulnrichment records proof-of-concept exploitation in its SSVC data. BlackTree has not independently executed or validated exploit material.",
            "epss": 0.80912,
            "epssPercentile": 0.99602,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path and a public exploit reference; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21299",
            "title": "Windows Kerberos Security Feature Bypass Vulnerability",
            "summary": "Windows Kerberos Security Feature Bypass Vulnerability",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02212,
            "epssPercentile": 0.81462,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21300",
            "title": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "summary": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02531,
            "epssPercentile": 0.83874,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21301",
            "title": "Windows Geolocation Service Information Disclosure Vulnerability",
            "summary": "Windows Geolocation Service Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01564,
            "epssPercentile": 0.73648,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21302",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21303",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21304",
            "title": "Microsoft DWM Core Library Elevation of Privilege Vulnerability",
            "summary": "Microsoft DWM Core Library Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00604,
            "epssPercentile": 0.46711,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21305",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21306",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70986,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21307",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01909,
            "epssPercentile": 0.7842,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21308",
            "title": "Windows Themes Spoofing Vulnerability",
            "summary": "Windows Themes Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02208,
            "epssPercentile": 0.81432,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21309",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.14979,
            "epssPercentile": 0.96482,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21310",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21312",
            "title": "Windows Smart Card Reader Information Disclosure Vulnerability",
            "summary": "Windows Smart Card Reader Information Disclosure Vulnerability",
            "score": 2.4,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00718,
            "epssPercentile": 0.51518,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21314",
            "title": "Windows SmartScreen Spoofing Vulnerability",
            "summary": "Windows SmartScreen Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01421,
            "epssPercentile": 0.71094,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21316",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58304,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21318",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21319",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21320",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21321",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21323",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0085,
            "epssPercentile": 0.55807,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21324",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21327",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21328",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01518,
            "epssPercentile": 0.72882,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21329",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01518,
            "epssPercentile": 0.72882,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21330",
            "title": "Windows Remote Desktop Services Denial of Service Vulnerability",
            "summary": "Windows Remote Desktop Services Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01961,
            "epssPercentile": 0.79002,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21331",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01019,
            "epssPercentile": 0.61089,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21332",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01474,
            "epssPercentile": 0.72107,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21336",
            "title": "Windows Cryptographic Information Disclosure Vulnerability",
            "summary": "Windows Cryptographic Information Disclosure Vulnerability",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00631,
            "epssPercentile": 0.47982,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21338",
            "title": "GDI+ Remote Code Execution Vulnerability",
            "summary": "GDI+ Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39683,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21339",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21340",
            "title": "Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability",
            "summary": "Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00452,
            "epssPercentile": 0.37841,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21341",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00698,
            "epssPercentile": 0.50753,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21374",
            "title": "Windows CSC Service Information Disclosure Vulnerability",
            "summary": "Windows CSC Service Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00587,
            "epssPercentile": 0.45949,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21378",
            "title": "Windows CSC Service Elevation of Privilege Vulnerability",
            "summary": "Windows CSC Service Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00564,
            "epssPercentile": 0.4479,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21382",
            "title": "Windows Graphics Component Elevation of Privilege Vulnerability",
            "summary": "Windows Graphics Component Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00503,
            "epssPercentile": 0.41206,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21389",
            "title": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "summary": "Uncontrolled resource consumption in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0194,
            "epssPercentile": 0.78785,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21409",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21411",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21413",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21417",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01171,
            "epssPercentile": 0.6537,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-windows-kb5050009",
      "slug": "microsoft-2025-01-windows-kb5050009",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5050009",
      "title": "Deploy Microsoft Windows security update KB5050009",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5050009",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, plus 1 more",
      "platform": "Windows",
      "release_version": "10.0.26100.2894",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21311",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, plus 1 more exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 125 linked CVEs for Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, plus 1 more. Microsoft reports exploitation for CVE-2025-21333, CVE-2025-21334, CVE-2025-21335.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 125,
        "ids": [
          "CVE-2025-21189",
          "CVE-2025-21193",
          "CVE-2025-21202",
          "CVE-2025-21207",
          "CVE-2025-21210",
          "CVE-2025-21211",
          "CVE-2025-21213",
          "CVE-2025-21214",
          "CVE-2025-21215",
          "CVE-2025-21217",
          "CVE-2025-21218",
          "CVE-2025-21219",
          "CVE-2025-21220",
          "CVE-2025-21223",
          "CVE-2025-21224",
          "CVE-2025-21225",
          "CVE-2025-21226",
          "CVE-2025-21227",
          "CVE-2025-21228",
          "CVE-2025-21229",
          "CVE-2025-21230",
          "CVE-2025-21231",
          "CVE-2025-21232",
          "CVE-2025-21233",
          "CVE-2025-21234",
          "CVE-2025-21235",
          "CVE-2025-21236",
          "CVE-2025-21237",
          "CVE-2025-21238",
          "CVE-2025-21239",
          "CVE-2025-21240",
          "CVE-2025-21241",
          "CVE-2025-21242",
          "CVE-2025-21243",
          "CVE-2025-21244",
          "CVE-2025-21245",
          "CVE-2025-21246",
          "CVE-2025-21248",
          "CVE-2025-21249",
          "CVE-2025-21250",
          "CVE-2025-21251",
          "CVE-2025-21252",
          "CVE-2025-21255",
          "CVE-2025-21256",
          "CVE-2025-21257",
          "CVE-2025-21258",
          "CVE-2025-21260",
          "CVE-2025-21261",
          "CVE-2025-21263",
          "CVE-2025-21265",
          "CVE-2025-21266",
          "CVE-2025-21268",
          "CVE-2025-21269",
          "CVE-2025-21270",
          "CVE-2025-21272",
          "CVE-2025-21273",
          "CVE-2025-21274",
          "CVE-2025-21275",
          "CVE-2025-21276",
          "CVE-2025-21277",
          "CVE-2025-21278",
          "CVE-2025-21280",
          "CVE-2025-21281",
          "CVE-2025-21282",
          "CVE-2025-21284",
          "CVE-2025-21285",
          "CVE-2025-21286",
          "CVE-2025-21287",
          "CVE-2025-21288",
          "CVE-2025-21289",
          "CVE-2025-21290",
          "CVE-2025-21292",
          "CVE-2025-21294",
          "CVE-2025-21295",
          "CVE-2025-21296",
          "CVE-2025-21297",
          "CVE-2025-21298",
          "CVE-2025-21299",
          "CVE-2025-21300",
          "CVE-2025-21301",
          "CVE-2025-21302",
          "CVE-2025-21303",
          "CVE-2025-21305",
          "CVE-2025-21306",
          "CVE-2025-21307",
          "CVE-2025-21308",
          "CVE-2025-21309",
          "CVE-2025-21310",
          "CVE-2025-21311",
          "CVE-2025-21313",
          "CVE-2025-21314",
          "CVE-2025-21315",
          "CVE-2025-21316",
          "CVE-2025-21317",
          "CVE-2025-21318",
          "CVE-2025-21319",
          "CVE-2025-21320",
          "CVE-2025-21321",
          "CVE-2025-21323",
          "CVE-2025-21324",
          "CVE-2025-21326",
          "CVE-2025-21327",
          "CVE-2025-21328",
          "CVE-2025-21329",
          "CVE-2025-21330",
          "CVE-2025-21332",
          "CVE-2025-21333",
          "CVE-2025-21334",
          "CVE-2025-21335",
          "CVE-2025-21336",
          "CVE-2025-21338",
          "CVE-2025-21339",
          "CVE-2025-21340",
          "CVE-2025-21341",
          "CVE-2025-21343",
          "CVE-2025-21370",
          "CVE-2025-21372",
          "CVE-2025-21374",
          "CVE-2025-21378",
          "CVE-2025-21382",
          "CVE-2025-21389",
          "CVE-2025-21409",
          "CVE-2025-21411",
          "CVE-2025-21413",
          "CVE-2025-21417"
        ],
        "details": [
          {
            "id": "CVE-2025-21189",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02971,
            "epssPercentile": 0.86348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21193",
            "title": "Active Directory Federation Server Spoofing Vulnerability",
            "summary": "Active Directory Federation Server Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00751,
            "epssPercentile": 0.5264,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21202",
            "title": "Windows Recovery Environment Agent Elevation of Privilege Vulnerability",
            "summary": "Windows Recovery Environment Agent Elevation of Privilege Vulnerability",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0088,
            "epssPercentile": 0.56753,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21207",
            "title": "Windows Connected Devices Platform Service (Cdpsvc) Denial of Service Vulnerability",
            "summary": "Windows Connected Devices Platform Service (Cdpsvc) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02108,
            "epssPercentile": 0.80554,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21210",
            "title": "Windows BitLocker Information Disclosure Vulnerability",
            "summary": "Windows BitLocker Information Disclosure Vulnerability",
            "score": 4.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01139,
            "epssPercentile": 0.64494,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21211",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Secure Boot Security Feature Bypass Vulnerability",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00773,
            "epssPercentile": 0.53349,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21213",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Secure Boot Security Feature Bypass Vulnerability",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0072,
            "epssPercentile": 0.51578,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21214",
            "title": "Windows BitLocker Information Disclosure Vulnerability",
            "summary": "Windows BitLocker Information Disclosure Vulnerability",
            "score": 4.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00713,
            "epssPercentile": 0.51333,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21215",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Secure Boot Security Feature Bypass Vulnerability",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00818,
            "epssPercentile": 0.5483,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21217",
            "title": "Windows NTLM Spoofing Vulnerability",
            "summary": "Windows NTLM Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01948,
            "epssPercentile": 0.78877,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21218",
            "title": "Windows Kerberos Denial of Service Vulnerability",
            "summary": "Windows Kerberos Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02589,
            "epssPercentile": 0.8425,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21219",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03017,
            "epssPercentile": 0.86549,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21220",
            "title": "Microsoft Message Queuing Information Disclosure Vulnerability",
            "summary": "Microsoft Message Queuing Information Disclosure Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02151,
            "epssPercentile": 0.80943,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21223",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01621,
            "epssPercentile": 0.74499,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21224",
            "title": "Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability",
            "summary": "Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01908,
            "epssPercentile": 0.78413,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21225",
            "title": "Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability",
            "summary": "Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01553,
            "epssPercentile": 0.73491,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21226",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00867,
            "epssPercentile": 0.5638,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21227",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21228",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21229",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21230",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02686,
            "epssPercentile": 0.84872,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21231",
            "title": "IP Helper Denial of Service Vulnerability",
            "summary": "IP Helper Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02591,
            "epssPercentile": 0.84283,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21232",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21233",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21234",
            "title": "Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability",
            "summary": "Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00598,
            "epssPercentile": 0.46439,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21235",
            "title": "Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability",
            "summary": "Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00596,
            "epssPercentile": 0.46331,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21236",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21237",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21238",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21239",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01489,
            "epssPercentile": 0.7238,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21240",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21241",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01489,
            "epssPercentile": 0.7238,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21242",
            "title": "Windows Kerberos Information Disclosure Vulnerability",
            "summary": "Windows Kerberos Information Disclosure Vulnerability",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01646,
            "epssPercentile": 0.74883,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21243",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21244",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21245",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21246",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21248",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01489,
            "epssPercentile": 0.72379,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21249",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21250",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21251",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02591,
            "epssPercentile": 0.84283,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21252",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21255",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21256",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21257",
            "title": "Windows WLAN AutoConfig Service Information Disclosure Vulnerability",
            "summary": "Windows WLAN AutoConfig Service Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00732,
            "epssPercentile": 0.51998,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21258",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21260",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55328,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21261",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21263",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21265",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21266",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21268",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01989,
            "epssPercentile": 0.79308,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21269",
            "title": "Windows HTML Platforms Security Feature Bypass Vulnerability",
            "summary": "Windows HTML Platforms Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.04593,
            "epssPercentile": 0.91034,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21270",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21272",
            "title": "Windows COM Server Information Disclosure Vulnerability",
            "summary": "Windows COM Server Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00706,
            "epssPercentile": 0.51085,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21273",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21274",
            "title": "Windows Event Tracing Denial of Service Vulnerability",
            "summary": "Windows Event Tracing Denial of Service Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00785,
            "epssPercentile": 0.53739,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21275",
            "title": "Windows App Package Installer Elevation of Privilege Vulnerability",
            "summary": "Windows App Package Installer Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00618,
            "epssPercentile": 0.47369,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21276",
            "title": "Windows MapUrlToZone Denial of Service Vulnerability",
            "summary": "Windows MapUrlToZone Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02421,
            "epssPercentile": 0.83098,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21277",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.38612,
            "epssPercentile": 0.98478,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21278",
            "title": "Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability",
            "summary": "Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0057,
            "epssPercentile": 0.45061,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21280",
            "title": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability",
            "summary": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49634,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21281",
            "title": "Microsoft COM for Windows Elevation of Privilege Vulnerability",
            "summary": "Microsoft COM for Windows Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00605,
            "epssPercentile": 0.46774,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21282",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21284",
            "title": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability",
            "summary": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49634,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21285",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.55686,
            "epssPercentile": 0.9897,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21286",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21287",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00549,
            "epssPercentile": 0.43984,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21288",
            "title": "Windows COM Server Information Disclosure Vulnerability",
            "summary": "Windows COM Server Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00706,
            "epssPercentile": 0.51085,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21289",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21290",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21292",
            "title": "Windows Search Service Elevation of Privilege Vulnerability",
            "summary": "Windows Search Service Elevation of Privilege Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00825,
            "epssPercentile": 0.55027,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21294",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01209,
            "epssPercentile": 0.66385,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21295",
            "title": "SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability",
            "summary": "SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0161,
            "epssPercentile": 0.74316,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21296",
            "title": "BranchCache Remote Code Execution Vulnerability",
            "summary": "BranchCache Remote Code Execution Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00778,
            "epssPercentile": 0.53536,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21297",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01436,
            "epssPercentile": 0.71362,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21298",
            "title": "Windows OLE Remote Code Execution Vulnerability",
            "summary": "Windows OLE Remote Code Execution Vulnerability",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "CISA Vulnrichment records proof-of-concept exploitation in its SSVC data. BlackTree has not independently executed or validated exploit material.",
            "epss": 0.80912,
            "epssPercentile": 0.99602,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path and a public exploit reference; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21299",
            "title": "Windows Kerberos Security Feature Bypass Vulnerability",
            "summary": "Windows Kerberos Security Feature Bypass Vulnerability",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02212,
            "epssPercentile": 0.81462,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21300",
            "title": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "summary": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02531,
            "epssPercentile": 0.83874,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21301",
            "title": "Windows Geolocation Service Information Disclosure Vulnerability",
            "summary": "Windows Geolocation Service Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01564,
            "epssPercentile": 0.73648,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21302",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21303",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21305",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21306",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70986,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21307",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01909,
            "epssPercentile": 0.7842,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21308",
            "title": "Windows Themes Spoofing Vulnerability",
            "summary": "Windows Themes Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02208,
            "epssPercentile": 0.81432,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21309",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.14979,
            "epssPercentile": 0.96482,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21310",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21311",
            "title": "Windows NTLM V1 Elevation of Privilege Vulnerability",
            "summary": "Windows NTLM V1 Elevation of Privilege Vulnerability",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0223,
            "epssPercentile": 0.8161,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21313",
            "title": "Windows Security Account Manager (SAM) Denial of Service Vulnerability",
            "summary": "Windows Security Account Manager (SAM) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01633,
            "epssPercentile": 0.74684,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21314",
            "title": "Windows SmartScreen Spoofing Vulnerability",
            "summary": "Windows SmartScreen Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01421,
            "epssPercentile": 0.71094,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21315",
            "title": "Microsoft Brokering File System Elevation of Privilege Vulnerability",
            "summary": "Microsoft Brokering File System Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00641,
            "epssPercentile": 0.48461,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21316",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58304,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21317",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0085,
            "epssPercentile": 0.55808,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21318",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21319",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21320",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21321",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21323",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0085,
            "epssPercentile": 0.55807,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21324",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21326",
            "title": "Internet Explorer Remote Code Execution Vulnerability",
            "summary": "Internet Explorer Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01316,
            "epssPercentile": 0.68883,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21327",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21328",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01518,
            "epssPercentile": 0.72882,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21329",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01518,
            "epssPercentile": 0.72882,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21330",
            "title": "Windows Remote Desktop Services Denial of Service Vulnerability",
            "summary": "Windows Remote Desktop Services Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01961,
            "epssPercentile": 0.79002,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21332",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01474,
            "epssPercentile": 0.72107,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21333",
            "title": "Microsoft Windows Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows Hyper-V NT Kernel Integration VSP contains a heap-based buffer overflow vulnerability that allows a local attacker to gain SYSTEM privileges.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-01-14.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.09988,
            "epssPercentile": 0.95287,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-02-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21334",
            "title": "Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability",
            "summary": "Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-01-14.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01561,
            "epssPercentile": 0.73599,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-02-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21335",
            "title": "Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability",
            "summary": "Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-01-14.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0139,
            "epssPercentile": 0.70518,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-02-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21336",
            "title": "Windows Cryptographic Information Disclosure Vulnerability",
            "summary": "Windows Cryptographic Information Disclosure Vulnerability",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00631,
            "epssPercentile": 0.47982,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21338",
            "title": "GDI+ Remote Code Execution Vulnerability",
            "summary": "GDI+ Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39683,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21339",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21340",
            "title": "Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability",
            "summary": "Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00452,
            "epssPercentile": 0.37841,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21341",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00698,
            "epssPercentile": 0.50753,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21343",
            "title": "Windows Web Threat Defense User Service Information Disclosure Vulnerability",
            "summary": "Windows Web Threat Defense User Service Information Disclosure Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01348,
            "epssPercentile": 0.6961,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21370",
            "title": "Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability",
            "summary": "Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00475,
            "epssPercentile": 0.39377,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21372",
            "title": "Microsoft Brokering File System Elevation of Privilege Vulnerability",
            "summary": "Microsoft Brokering File System Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00398,
            "epssPercentile": 0.33078,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21374",
            "title": "Windows CSC Service Information Disclosure Vulnerability",
            "summary": "Windows CSC Service Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00587,
            "epssPercentile": 0.45949,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21378",
            "title": "Windows CSC Service Elevation of Privilege Vulnerability",
            "summary": "Windows CSC Service Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00564,
            "epssPercentile": 0.4479,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21382",
            "title": "Windows Graphics Component Elevation of Privilege Vulnerability",
            "summary": "Windows Graphics Component Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00503,
            "epssPercentile": 0.41206,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21389",
            "title": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "summary": "Uncontrolled resource consumption in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0194,
            "epssPercentile": 0.78785,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21409",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21411",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21413",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21417",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01171,
            "epssPercentile": 0.6537,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-windows-kb5050013",
      "slug": "microsoft-2025-01-windows-kb5050013",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5050013",
      "title": "Deploy Microsoft Windows security update KB5050013",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5050013",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Windows 10 for 32-bit Systems, Windows 10 for x64-based Systems",
      "platform": "Windows",
      "release_version": "10.0.10240.20890",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21307",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows 10 for 32-bit Systems, Windows 10 for x64-based Systems exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 101 linked CVEs for Windows 10 for 32-bit Systems, Windows 10 for x64-based Systems. Microsoft marks CVE-2025-21308 as publicly disclosed, without that disclosure alone changing the BlackTree action window.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 101,
        "ids": [
          "CVE-2025-21189",
          "CVE-2025-21202",
          "CVE-2025-21210",
          "CVE-2025-21211",
          "CVE-2025-21213",
          "CVE-2025-21214",
          "CVE-2025-21215",
          "CVE-2025-21217",
          "CVE-2025-21219",
          "CVE-2025-21220",
          "CVE-2025-21223",
          "CVE-2025-21226",
          "CVE-2025-21227",
          "CVE-2025-21228",
          "CVE-2025-21229",
          "CVE-2025-21230",
          "CVE-2025-21231",
          "CVE-2025-21232",
          "CVE-2025-21233",
          "CVE-2025-21236",
          "CVE-2025-21237",
          "CVE-2025-21238",
          "CVE-2025-21239",
          "CVE-2025-21240",
          "CVE-2025-21241",
          "CVE-2025-21242",
          "CVE-2025-21243",
          "CVE-2025-21244",
          "CVE-2025-21245",
          "CVE-2025-21246",
          "CVE-2025-21248",
          "CVE-2025-21249",
          "CVE-2025-21250",
          "CVE-2025-21251",
          "CVE-2025-21252",
          "CVE-2025-21255",
          "CVE-2025-21256",
          "CVE-2025-21258",
          "CVE-2025-21260",
          "CVE-2025-21261",
          "CVE-2025-21263",
          "CVE-2025-21265",
          "CVE-2025-21266",
          "CVE-2025-21268",
          "CVE-2025-21269",
          "CVE-2025-21270",
          "CVE-2025-21272",
          "CVE-2025-21273",
          "CVE-2025-21274",
          "CVE-2025-21276",
          "CVE-2025-21277",
          "CVE-2025-21278",
          "CVE-2025-21280",
          "CVE-2025-21281",
          "CVE-2025-21282",
          "CVE-2025-21284",
          "CVE-2025-21285",
          "CVE-2025-21286",
          "CVE-2025-21287",
          "CVE-2025-21288",
          "CVE-2025-21289",
          "CVE-2025-21290",
          "CVE-2025-21293",
          "CVE-2025-21294",
          "CVE-2025-21295",
          "CVE-2025-21296",
          "CVE-2025-21298",
          "CVE-2025-21299",
          "CVE-2025-21300",
          "CVE-2025-21301",
          "CVE-2025-21302",
          "CVE-2025-21303",
          "CVE-2025-21305",
          "CVE-2025-21306",
          "CVE-2025-21307",
          "CVE-2025-21308",
          "CVE-2025-21310",
          "CVE-2025-21312",
          "CVE-2025-21316",
          "CVE-2025-21318",
          "CVE-2025-21319",
          "CVE-2025-21320",
          "CVE-2025-21321",
          "CVE-2025-21323",
          "CVE-2025-21324",
          "CVE-2025-21327",
          "CVE-2025-21328",
          "CVE-2025-21329",
          "CVE-2025-21331",
          "CVE-2025-21332",
          "CVE-2025-21336",
          "CVE-2025-21338",
          "CVE-2025-21339",
          "CVE-2025-21341",
          "CVE-2025-21374",
          "CVE-2025-21378",
          "CVE-2025-21389",
          "CVE-2025-21409",
          "CVE-2025-21411",
          "CVE-2025-21413",
          "CVE-2025-21417"
        ],
        "details": [
          {
            "id": "CVE-2025-21189",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02971,
            "epssPercentile": 0.86348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21202",
            "title": "Windows Recovery Environment Agent Elevation of Privilege Vulnerability",
            "summary": "Windows Recovery Environment Agent Elevation of Privilege Vulnerability",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0088,
            "epssPercentile": 0.56753,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21210",
            "title": "Windows BitLocker Information Disclosure Vulnerability",
            "summary": "Windows BitLocker Information Disclosure Vulnerability",
            "score": 4.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01139,
            "epssPercentile": 0.64494,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21211",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Secure Boot Security Feature Bypass Vulnerability",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00773,
            "epssPercentile": 0.53349,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21213",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Secure Boot Security Feature Bypass Vulnerability",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0072,
            "epssPercentile": 0.51578,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21214",
            "title": "Windows BitLocker Information Disclosure Vulnerability",
            "summary": "Windows BitLocker Information Disclosure Vulnerability",
            "score": 4.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00713,
            "epssPercentile": 0.51333,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21215",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Secure Boot Security Feature Bypass Vulnerability",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00818,
            "epssPercentile": 0.5483,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21217",
            "title": "Windows NTLM Spoofing Vulnerability",
            "summary": "Windows NTLM Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01948,
            "epssPercentile": 0.78877,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21219",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03017,
            "epssPercentile": 0.86549,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21220",
            "title": "Microsoft Message Queuing Information Disclosure Vulnerability",
            "summary": "Microsoft Message Queuing Information Disclosure Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02151,
            "epssPercentile": 0.80943,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21223",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01621,
            "epssPercentile": 0.74499,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21226",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00867,
            "epssPercentile": 0.5638,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21227",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21228",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21229",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21230",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02686,
            "epssPercentile": 0.84872,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21231",
            "title": "IP Helper Denial of Service Vulnerability",
            "summary": "IP Helper Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02591,
            "epssPercentile": 0.84283,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21232",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21233",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21236",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21237",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21238",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21239",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01489,
            "epssPercentile": 0.7238,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21240",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21241",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01489,
            "epssPercentile": 0.7238,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21242",
            "title": "Windows Kerberos Information Disclosure Vulnerability",
            "summary": "Windows Kerberos Information Disclosure Vulnerability",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01646,
            "epssPercentile": 0.74883,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21243",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21244",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21245",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21246",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21248",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01489,
            "epssPercentile": 0.72379,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21249",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21250",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21251",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02591,
            "epssPercentile": 0.84283,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21252",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21255",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21256",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21258",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21260",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55328,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21261",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21263",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21265",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21266",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21268",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01989,
            "epssPercentile": 0.79308,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21269",
            "title": "Windows HTML Platforms Security Feature Bypass Vulnerability",
            "summary": "Windows HTML Platforms Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.04593,
            "epssPercentile": 0.91034,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21270",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21272",
            "title": "Windows COM Server Information Disclosure Vulnerability",
            "summary": "Windows COM Server Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00706,
            "epssPercentile": 0.51085,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21273",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21274",
            "title": "Windows Event Tracing Denial of Service Vulnerability",
            "summary": "Windows Event Tracing Denial of Service Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00785,
            "epssPercentile": 0.53739,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21276",
            "title": "Windows MapUrlToZone Denial of Service Vulnerability",
            "summary": "Windows MapUrlToZone Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02421,
            "epssPercentile": 0.83098,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21277",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.38612,
            "epssPercentile": 0.98478,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21278",
            "title": "Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability",
            "summary": "Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0057,
            "epssPercentile": 0.45061,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21280",
            "title": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability",
            "summary": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49634,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21281",
            "title": "Microsoft COM for Windows Elevation of Privilege Vulnerability",
            "summary": "Microsoft COM for Windows Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00605,
            "epssPercentile": 0.46774,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21282",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21284",
            "title": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability",
            "summary": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49634,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21285",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.55686,
            "epssPercentile": 0.9897,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21286",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21287",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00549,
            "epssPercentile": 0.43984,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21288",
            "title": "Windows COM Server Information Disclosure Vulnerability",
            "summary": "Windows COM Server Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00706,
            "epssPercentile": 0.51085,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21289",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21290",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21293",
            "title": "Active Directory Domain Services Elevation of Privilege Vulnerability",
            "summary": "Active Directory Domain Services Elevation of Privilege Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.18825,
            "epssPercentile": 0.97091,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21294",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01209,
            "epssPercentile": 0.66385,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21295",
            "title": "SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability",
            "summary": "SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0161,
            "epssPercentile": 0.74316,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21296",
            "title": "BranchCache Remote Code Execution Vulnerability",
            "summary": "BranchCache Remote Code Execution Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00778,
            "epssPercentile": 0.53536,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21298",
            "title": "Windows OLE Remote Code Execution Vulnerability",
            "summary": "Windows OLE Remote Code Execution Vulnerability",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "CISA Vulnrichment records proof-of-concept exploitation in its SSVC data. BlackTree has not independently executed or validated exploit material.",
            "epss": 0.80912,
            "epssPercentile": 0.99602,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path and a public exploit reference; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21299",
            "title": "Windows Kerberos Security Feature Bypass Vulnerability",
            "summary": "Windows Kerberos Security Feature Bypass Vulnerability",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02212,
            "epssPercentile": 0.81462,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21300",
            "title": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "summary": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02531,
            "epssPercentile": 0.83874,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21301",
            "title": "Windows Geolocation Service Information Disclosure Vulnerability",
            "summary": "Windows Geolocation Service Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01564,
            "epssPercentile": 0.73648,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21302",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21303",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21305",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21306",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70986,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21307",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01909,
            "epssPercentile": 0.7842,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21308",
            "title": "Windows Themes Spoofing Vulnerability",
            "summary": "Windows Themes Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02208,
            "epssPercentile": 0.81432,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21310",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21312",
            "title": "Windows Smart Card Reader Information Disclosure Vulnerability",
            "summary": "Windows Smart Card Reader Information Disclosure Vulnerability",
            "score": 2.4,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00718,
            "epssPercentile": 0.51518,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21316",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58304,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21318",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21319",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21320",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21321",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21323",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0085,
            "epssPercentile": 0.55807,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21324",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21327",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21328",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01518,
            "epssPercentile": 0.72882,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21329",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01518,
            "epssPercentile": 0.72882,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21331",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01019,
            "epssPercentile": 0.61089,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21332",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01474,
            "epssPercentile": 0.72107,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21336",
            "title": "Windows Cryptographic Information Disclosure Vulnerability",
            "summary": "Windows Cryptographic Information Disclosure Vulnerability",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00631,
            "epssPercentile": 0.47982,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21338",
            "title": "GDI+ Remote Code Execution Vulnerability",
            "summary": "GDI+ Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39683,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21339",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21341",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00698,
            "epssPercentile": 0.50753,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21374",
            "title": "Windows CSC Service Information Disclosure Vulnerability",
            "summary": "Windows CSC Service Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00587,
            "epssPercentile": 0.45949,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21378",
            "title": "Windows CSC Service Elevation of Privilege Vulnerability",
            "summary": "Windows CSC Service Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00564,
            "epssPercentile": 0.4479,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21389",
            "title": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "summary": "Uncontrolled resource consumption in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0194,
            "epssPercentile": 0.78785,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21409",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21411",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21413",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21417",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01171,
            "epssPercentile": 0.6537,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-windows-kb5050021",
      "slug": "microsoft-2025-01-windows-kb5050021",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5050021",
      "title": "Deploy Microsoft Windows security update KB5050021",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5050021",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Windows 11 Version 23H2 for ARM64-based Systems, Windows 11 Version 23H2 for x64-based Systems",
      "platform": "Windows",
      "release_version": "10.0.22631.4751",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21307",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows 11 Version 23H2 for ARM64-based Systems, Windows 11 Version 23H2 for x64-based Systems exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 119 linked CVEs for Windows 11 Version 23H2 for ARM64-based Systems, Windows 11 Version 23H2 for x64-based Systems. Microsoft reports exploitation for CVE-2025-21333, CVE-2025-21334, CVE-2025-21335.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 119,
        "ids": [
          "CVE-2025-21189",
          "CVE-2025-21202",
          "CVE-2025-21207",
          "CVE-2025-21210",
          "CVE-2025-21211",
          "CVE-2025-21213",
          "CVE-2025-21214",
          "CVE-2025-21215",
          "CVE-2025-21217",
          "CVE-2025-21219",
          "CVE-2025-21220",
          "CVE-2025-21223",
          "CVE-2025-21224",
          "CVE-2025-21226",
          "CVE-2025-21227",
          "CVE-2025-21228",
          "CVE-2025-21229",
          "CVE-2025-21230",
          "CVE-2025-21231",
          "CVE-2025-21232",
          "CVE-2025-21233",
          "CVE-2025-21234",
          "CVE-2025-21235",
          "CVE-2025-21236",
          "CVE-2025-21237",
          "CVE-2025-21238",
          "CVE-2025-21239",
          "CVE-2025-21240",
          "CVE-2025-21241",
          "CVE-2025-21242",
          "CVE-2025-21243",
          "CVE-2025-21244",
          "CVE-2025-21245",
          "CVE-2025-21246",
          "CVE-2025-21248",
          "CVE-2025-21249",
          "CVE-2025-21250",
          "CVE-2025-21251",
          "CVE-2025-21252",
          "CVE-2025-21255",
          "CVE-2025-21256",
          "CVE-2025-21257",
          "CVE-2025-21258",
          "CVE-2025-21260",
          "CVE-2025-21261",
          "CVE-2025-21263",
          "CVE-2025-21265",
          "CVE-2025-21266",
          "CVE-2025-21268",
          "CVE-2025-21269",
          "CVE-2025-21270",
          "CVE-2025-21272",
          "CVE-2025-21273",
          "CVE-2025-21274",
          "CVE-2025-21275",
          "CVE-2025-21276",
          "CVE-2025-21277",
          "CVE-2025-21278",
          "CVE-2025-21280",
          "CVE-2025-21281",
          "CVE-2025-21282",
          "CVE-2025-21284",
          "CVE-2025-21285",
          "CVE-2025-21286",
          "CVE-2025-21287",
          "CVE-2025-21288",
          "CVE-2025-21289",
          "CVE-2025-21290",
          "CVE-2025-21291",
          "CVE-2025-21292",
          "CVE-2025-21293",
          "CVE-2025-21294",
          "CVE-2025-21295",
          "CVE-2025-21296",
          "CVE-2025-21298",
          "CVE-2025-21299",
          "CVE-2025-21300",
          "CVE-2025-21301",
          "CVE-2025-21302",
          "CVE-2025-21303",
          "CVE-2025-21305",
          "CVE-2025-21306",
          "CVE-2025-21307",
          "CVE-2025-21308",
          "CVE-2025-21310",
          "CVE-2025-21312",
          "CVE-2025-21314",
          "CVE-2025-21316",
          "CVE-2025-21317",
          "CVE-2025-21318",
          "CVE-2025-21319",
          "CVE-2025-21320",
          "CVE-2025-21321",
          "CVE-2025-21323",
          "CVE-2025-21324",
          "CVE-2025-21327",
          "CVE-2025-21328",
          "CVE-2025-21329",
          "CVE-2025-21330",
          "CVE-2025-21331",
          "CVE-2025-21332",
          "CVE-2025-21333",
          "CVE-2025-21334",
          "CVE-2025-21335",
          "CVE-2025-21336",
          "CVE-2025-21338",
          "CVE-2025-21339",
          "CVE-2025-21340",
          "CVE-2025-21341",
          "CVE-2025-21343",
          "CVE-2025-21370",
          "CVE-2025-21374",
          "CVE-2025-21378",
          "CVE-2025-21382",
          "CVE-2025-21389",
          "CVE-2025-21409",
          "CVE-2025-21411",
          "CVE-2025-21413",
          "CVE-2025-21417"
        ],
        "details": [
          {
            "id": "CVE-2025-21189",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02971,
            "epssPercentile": 0.86348,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21202",
            "title": "Windows Recovery Environment Agent Elevation of Privilege Vulnerability",
            "summary": "Windows Recovery Environment Agent Elevation of Privilege Vulnerability",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0088,
            "epssPercentile": 0.56753,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21207",
            "title": "Windows Connected Devices Platform Service (Cdpsvc) Denial of Service Vulnerability",
            "summary": "Windows Connected Devices Platform Service (Cdpsvc) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02108,
            "epssPercentile": 0.80554,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21210",
            "title": "Windows BitLocker Information Disclosure Vulnerability",
            "summary": "Windows BitLocker Information Disclosure Vulnerability",
            "score": 4.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01139,
            "epssPercentile": 0.64494,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21211",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Secure Boot Security Feature Bypass Vulnerability",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00773,
            "epssPercentile": 0.53349,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21213",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Secure Boot Security Feature Bypass Vulnerability",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0072,
            "epssPercentile": 0.51578,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21214",
            "title": "Windows BitLocker Information Disclosure Vulnerability",
            "summary": "Windows BitLocker Information Disclosure Vulnerability",
            "score": 4.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00713,
            "epssPercentile": 0.51333,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21215",
            "title": "Secure Boot Security Feature Bypass Vulnerability",
            "summary": "Secure Boot Security Feature Bypass Vulnerability",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00818,
            "epssPercentile": 0.5483,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21217",
            "title": "Windows NTLM Spoofing Vulnerability",
            "summary": "Windows NTLM Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01948,
            "epssPercentile": 0.78877,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21219",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03017,
            "epssPercentile": 0.86549,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21220",
            "title": "Microsoft Message Queuing Information Disclosure Vulnerability",
            "summary": "Microsoft Message Queuing Information Disclosure Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02151,
            "epssPercentile": 0.80943,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21223",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01621,
            "epssPercentile": 0.74499,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21224",
            "title": "Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability",
            "summary": "Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01908,
            "epssPercentile": 0.78413,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21226",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00867,
            "epssPercentile": 0.5638,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21227",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21228",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21229",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21230",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02686,
            "epssPercentile": 0.84872,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21231",
            "title": "IP Helper Denial of Service Vulnerability",
            "summary": "IP Helper Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02591,
            "epssPercentile": 0.84283,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21232",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21233",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21234",
            "title": "Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability",
            "summary": "Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00598,
            "epssPercentile": 0.46439,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21235",
            "title": "Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability",
            "summary": "Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00596,
            "epssPercentile": 0.46331,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21236",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21237",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21238",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21239",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01489,
            "epssPercentile": 0.7238,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21240",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21241",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01489,
            "epssPercentile": 0.7238,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21242",
            "title": "Windows Kerberos Information Disclosure Vulnerability",
            "summary": "Windows Kerberos Information Disclosure Vulnerability",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01646,
            "epssPercentile": 0.74883,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21243",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21244",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21245",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75483,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21246",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21248",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01489,
            "epssPercentile": 0.72379,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21249",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21250",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01685,
            "epssPercentile": 0.75484,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21251",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02591,
            "epssPercentile": 0.84283,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21252",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21255",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21256",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21257",
            "title": "Windows WLAN AutoConfig Service Information Disclosure Vulnerability",
            "summary": "Windows WLAN AutoConfig Service Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00732,
            "epssPercentile": 0.51998,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21258",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55327,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21260",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55328,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21261",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21263",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21265",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21266",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21268",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01989,
            "epssPercentile": 0.79308,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21269",
            "title": "Windows HTML Platforms Security Feature Bypass Vulnerability",
            "summary": "Windows HTML Platforms Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.04593,
            "epssPercentile": 0.91034,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21270",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21272",
            "title": "Windows COM Server Information Disclosure Vulnerability",
            "summary": "Windows COM Server Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00706,
            "epssPercentile": 0.51085,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21273",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21274",
            "title": "Windows Event Tracing Denial of Service Vulnerability",
            "summary": "Windows Event Tracing Denial of Service Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00785,
            "epssPercentile": 0.53739,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21275",
            "title": "Windows App Package Installer Elevation of Privilege Vulnerability",
            "summary": "Windows App Package Installer Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00618,
            "epssPercentile": 0.47369,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21276",
            "title": "Windows MapUrlToZone Denial of Service Vulnerability",
            "summary": "Windows MapUrlToZone Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02421,
            "epssPercentile": 0.83098,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21277",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.38612,
            "epssPercentile": 0.98478,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21278",
            "title": "Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability",
            "summary": "Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability",
            "score": 6.2,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0057,
            "epssPercentile": 0.45061,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21280",
            "title": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability",
            "summary": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49634,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21281",
            "title": "Microsoft COM for Windows Elevation of Privilege Vulnerability",
            "summary": "Microsoft COM for Windows Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00605,
            "epssPercentile": 0.46774,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21282",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21284",
            "title": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability",
            "summary": "Windows Virtual Trusted Platform Module Denial of Service Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49634,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21285",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.55686,
            "epssPercentile": 0.9897,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21286",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01267,
            "epssPercentile": 0.67831,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21287",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00549,
            "epssPercentile": 0.43984,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21288",
            "title": "Windows COM Server Information Disclosure Vulnerability",
            "summary": "Windows COM Server Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00706,
            "epssPercentile": 0.51085,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21289",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21290",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02395,
            "epssPercentile": 0.82905,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21291",
            "title": "Windows Direct Show Remote Code Execution Vulnerability",
            "summary": "Windows Direct Show Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01396,
            "epssPercentile": 0.70616,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21292",
            "title": "Windows Search Service Elevation of Privilege Vulnerability",
            "summary": "Windows Search Service Elevation of Privilege Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00825,
            "epssPercentile": 0.55027,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21293",
            "title": "Active Directory Domain Services Elevation of Privilege Vulnerability",
            "summary": "Active Directory Domain Services Elevation of Privilege Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.18825,
            "epssPercentile": 0.97091,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21294",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01209,
            "epssPercentile": 0.66385,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21295",
            "title": "SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability",
            "summary": "SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0161,
            "epssPercentile": 0.74316,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21296",
            "title": "BranchCache Remote Code Execution Vulnerability",
            "summary": "BranchCache Remote Code Execution Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00778,
            "epssPercentile": 0.53536,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21298",
            "title": "Windows OLE Remote Code Execution Vulnerability",
            "summary": "Windows OLE Remote Code Execution Vulnerability",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "CISA Vulnrichment records proof-of-concept exploitation in its SSVC data. BlackTree has not independently executed or validated exploit material.",
            "epss": 0.80912,
            "epssPercentile": 0.99602,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path and a public exploit reference; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21299",
            "title": "Windows Kerberos Security Feature Bypass Vulnerability",
            "summary": "Windows Kerberos Security Feature Bypass Vulnerability",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02212,
            "epssPercentile": 0.81462,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21300",
            "title": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "summary": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02531,
            "epssPercentile": 0.83874,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21301",
            "title": "Windows Geolocation Service Information Disclosure Vulnerability",
            "summary": "Windows Geolocation Service Information Disclosure Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01564,
            "epssPercentile": 0.73648,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21302",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21303",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21305",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70987,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21306",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01415,
            "epssPercentile": 0.70986,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21307",
            "title": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "summary": "Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01909,
            "epssPercentile": 0.7842,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21308",
            "title": "Windows Themes Spoofing Vulnerability",
            "summary": "Windows Themes Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02208,
            "epssPercentile": 0.81432,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21310",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55325,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21312",
            "title": "Windows Smart Card Reader Information Disclosure Vulnerability",
            "summary": "Windows Smart Card Reader Information Disclosure Vulnerability",
            "score": 2.4,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00718,
            "epssPercentile": 0.51518,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21314",
            "title": "Windows SmartScreen Spoofing Vulnerability",
            "summary": "Windows SmartScreen Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01421,
            "epssPercentile": 0.71094,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21316",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58304,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21317",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0085,
            "epssPercentile": 0.55808,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21318",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21319",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21320",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21321",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58303,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21323",
            "title": "Windows Kernel Memory Information Disclosure Vulnerability",
            "summary": "Windows Kernel Memory Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0085,
            "epssPercentile": 0.55807,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21324",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00834,
            "epssPercentile": 0.55326,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21327",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00759,
            "epssPercentile": 0.52933,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21328",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01518,
            "epssPercentile": 0.72882,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21329",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01518,
            "epssPercentile": 0.72882,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21330",
            "title": "Windows Remote Desktop Services Denial of Service Vulnerability",
            "summary": "Windows Remote Desktop Services Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01961,
            "epssPercentile": 0.79002,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21331",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01019,
            "epssPercentile": 0.61089,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21332",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "MapUrlToZone Security Feature Bypass Vulnerability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01474,
            "epssPercentile": 0.72107,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21333",
            "title": "Microsoft Windows Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows Hyper-V NT Kernel Integration VSP contains a heap-based buffer overflow vulnerability that allows a local attacker to gain SYSTEM privileges.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-01-14.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.09988,
            "epssPercentile": 0.95287,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-02-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21334",
            "title": "Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability",
            "summary": "Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-01-14.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01561,
            "epssPercentile": 0.73599,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-02-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21335",
            "title": "Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability",
            "summary": "Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-01-14.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0139,
            "epssPercentile": 0.70518,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-02-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21336",
            "title": "Windows Cryptographic Information Disclosure Vulnerability",
            "summary": "Windows Cryptographic Information Disclosure Vulnerability",
            "score": 5.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00631,
            "epssPercentile": 0.47982,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21338",
            "title": "GDI+ Remote Code Execution Vulnerability",
            "summary": "GDI+ Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00479,
            "epssPercentile": 0.39683,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21339",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21340",
            "title": "Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability",
            "summary": "Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00452,
            "epssPercentile": 0.37841,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21341",
            "title": "Windows Digital Media Elevation of Privilege Vulnerability",
            "summary": "Windows Digital Media Elevation of Privilege Vulnerability",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00698,
            "epssPercentile": 0.50753,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21343",
            "title": "Windows Web Threat Defense User Service Information Disclosure Vulnerability",
            "summary": "Windows Web Threat Defense User Service Information Disclosure Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01348,
            "epssPercentile": 0.6961,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21370",
            "title": "Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability",
            "summary": "Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00475,
            "epssPercentile": 0.39377,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21374",
            "title": "Windows CSC Service Information Disclosure Vulnerability",
            "summary": "Windows CSC Service Information Disclosure Vulnerability",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00587,
            "epssPercentile": 0.45949,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21378",
            "title": "Windows CSC Service Elevation of Privilege Vulnerability",
            "summary": "Windows CSC Service Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00564,
            "epssPercentile": 0.4479,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21382",
            "title": "Windows Graphics Component Elevation of Privilege Vulnerability",
            "summary": "Windows Graphics Component Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00503,
            "epssPercentile": 0.41206,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21389",
            "title": "Windows Universal Plug and Play (UPnP) Device Host Denial of Service Vulnerability",
            "summary": "Uncontrolled resource consumption in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to deny service over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0194,
            "epssPercentile": 0.78785,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21409",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21411",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21413",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01107,
            "epssPercentile": 0.63691,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21417",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01171,
            "epssPercentile": 0.6537,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-windows-kb5065426",
      "slug": "microsoft-2025-01-windows-kb5065426",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5065426",
      "title": "Deploy Microsoft Windows security update KB5065426",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5065426",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, plus 1 more",
      "platform": "Windows",
      "release_version": "10.0.26100.6584",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21293",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, plus 1 more exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, plus 1 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21293"
        ],
        "details": [
          {
            "id": "CVE-2025-21293",
            "title": "Active Directory Domain Services Elevation of Privilege Vulnerability",
            "summary": "Active Directory Domain Services Elevation of Privilege Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.18825,
            "epssPercentile": 0.97091,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-windows-kb5065474",
      "slug": "microsoft-2025-01-windows-kb5065474",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5065474",
      "title": "Deploy Microsoft Windows security update KB5065474",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5065474",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, plus 1 more",
      "platform": "Windows",
      "release_version": "10.0.26100.6508",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21293",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, plus 1 more exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, plus 1 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21293"
        ],
        "details": [
          {
            "id": "CVE-2025-21293",
            "title": "Active Directory Domain Services Elevation of Privilege Vulnerability",
            "summary": "Active Directory Domain Services Elevation of Privilege Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.18825,
            "epssPercentile": 0.97091,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-01-windows-kb5095051",
      "slug": "microsoft-2025-01-windows-kb5095051",
      "cycle_id": "2025-01",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5095051",
      "title": "Deploy Microsoft Windows security update KB5095051",
      "source_title": "2025-01 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5095051",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "Windows 11 Version 26H1 for ARM64-based Systems, Windows 11 version 26H1 for x64-based Systems",
      "platform": "Windows",
      "release_version": "10.0.28000.2269",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.5,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21330",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows 11 Version 26H1 for ARM64-based Systems, Windows 11 version 26H1 for x64-based Systems exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows 11 Version 26H1 for ARM64-based Systems, Windows 11 version 26H1 for x64-based Systems.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21330"
        ],
        "details": [
          {
            "id": "CVE-2025-21330",
            "title": "Windows Remote Desktop Services Denial of Service Vulnerability",
            "summary": "Windows Remote Desktop Services Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01961,
            "epssPercentile": 0.79002,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-01-3472837",
      "slug": "sap-2025-01-3472837",
      "cycle_id": "2025-01",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3472837",
      "title": "Assess and apply SAP security advisory 3472837",
      "source_title": "[CVE-2025-0055] Information Disclosure vulnerability in SAP GUI for Windows Product- SAP GUI for Windows, Versions – BC-FES-GUI 8.0",
      "source_url": "https://me.sap.com/notes/3472837",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "SAP GUI for Windows, Versions – BC-FES-GUI 8.0",
      "platform": "SAP",
      "release_version": "s – BC-FES-GUI 8.0",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 6.0",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 6,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-0055",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP GUI for Windows, Versions – BC-FES-GUI 8.0 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3472837 in its 2025-01 Security Patch Day release for SAP GUI for Windows, Versions – BC-FES-GUI 8.0. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-0055"
        ],
        "details": [
          {
            "id": "CVE-2025-0055",
            "title": "Information Disclosure vulnerability in SAP GUI for Windows",
            "summary": "SAP GUI for Windows stores user input on the client PC to improve usability. Under very specific circumstances an attacker with administrative privileges or access to the victim�s user directory on the Operating System level would be able to read this data. Depending on the user input provided in transactions, the disclosed data could range from non-critical data to highly sensitive data, causing high impact on confi",
            "score": 6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00243,
            "epssPercentile": 0.15457,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-01-3474398",
      "slug": "sap-2025-01-3474398",
      "cycle_id": "2025-01",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3474398",
      "title": "Assess and apply SAP security advisory 3474398",
      "source_title": "[CVE-2025-0061] Multiple vulnerabilities in SAP BusinessObjects Business Intelligence Platform Additional CVE - CVE-2025-0060 Product- SAP BusinessObjects Business Intelligence Platform, Versions – ENTERPRISE 420, 430, 2025",
      "source_url": "https://me.sap.com/notes/3474398",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "SAP BusinessObjects Business Intelligence Platform, Versions – ENTERPRISE 420, 430, 2025",
      "platform": "SAP",
      "release_version": "s – ENTERPRISE 420, 430, 2025",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "High; CVSS 8.7",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.7,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-0061",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP BusinessObjects Business Intelligence Platform, Versions – ENTERPRISE 420, 430, 2025 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3474398 in its 2025-01 Security Patch Day release for SAP BusinessObjects Business Intelligence Platform, Versions – ENTERPRISE 420, 430, 2025. The public bulletin links 2 CVEs; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 2,
        "ids": [
          "CVE-2025-0060",
          "CVE-2025-0061"
        ],
        "details": [
          {
            "id": "CVE-2025-0060",
            "title": "Multiple vulnerabilities in SAP BusinessObjects Business Intelligence Platform",
            "summary": "SAP BusinessObjects Business Intelligence Platform allows an authenticated user with restricted access to inject malicious JS code which can read sensitive information from the server and send it to the attacker. The attacker could further use this information to impersonate as a high privileged user causing high impact on confidentiality and integrity of the application.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00401,
            "epssPercentile": 0.33387,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-0061",
            "title": "Multiple vulnerabilities in SAP BusinessObjects Business Intelligence Platform",
            "summary": "SAP BusinessObjects Business Intelligence Platform allows an unauthenticated attacker to perform session hijacking over the network without any user interaction, due to an information disclosure vulnerability. Attacker can access and modify all the data of the application.",
            "score": 8.7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00505,
            "epssPercentile": 0.41332,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-01-3492169-opens-in-new-tab",
      "slug": "sap-2025-01-3492169-opens-in-new-tab",
      "cycle_id": "2025-01",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3492169(opens in new tab)",
      "title": "Assess and apply SAP security advisory 3492169(opens in new tab)",
      "source_title": "Multiple Buffer overflow vulnerabilities in SAP BusinessObjects Business Intelligence Platform (Crystal Reports for Enterprise) Related CVEs - CVE-2024-29131, CVE-2024-29133 | Product - SAP BusinessObjects Business Intelligence Platform (Crystal Reports for Enterprise), Version - ENTERPRISE 430",
      "source_url": "https://me.sap.com/notes/3492169",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "SAP BusinessObjects Business Intelligence Platform (Crystal Reports for Enterprise), Version - ENTERPRISE 430",
      "platform": "SAP",
      "release_version": "ENTERPRISE 430",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Low; CVSS 2.2",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2024-29131",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP BusinessObjects Business Intelligence Platform (Crystal Reports for Enterprise), Version - ENTERPRISE 430 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3492169(opens in new tab) in its 2025-01 Security Patch Day release for SAP BusinessObjects Business Intelligence Platform (Crystal Reports for Enterprise), Version - ENTERPRISE 430. The public bulletin links 2 CVEs; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 2,
        "ids": [
          "CVE-2024-29131",
          "CVE-2024-29133"
        ],
        "details": [
          {
            "id": "CVE-2024-29131",
            "title": "Apache Commons Configuration: StackOverflowError adding property in AbstractListDelimiterHandler.flattenIterator()",
            "summary": "Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which fixes the issue.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02054,
            "epssPercentile": 0.8001,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2024-29133",
            "title": "Apache Commons Configuration: StackOverflowError calling ListDelimiterHandler.flatten(Object, int) with a cyclical object tree",
            "summary": "Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which fixes the issue.",
            "score": 5.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01727,
            "epssPercentile": 0.7604,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-01-3502459",
      "slug": "sap-2025-01-3502459",
      "cycle_id": "2025-01",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3502459",
      "title": "Assess and apply SAP security advisory 3502459",
      "source_title": "[CVE-2025-0056] Information Disclosure vulnerability in SAP GUI for Java Product- SAP GUI for Java, Versions – BC-FES-JAV 7.80",
      "source_url": "https://me.sap.com/notes/3502459",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "SAP GUI for Java, Versions – BC-FES-JAV 7.80",
      "platform": "SAP",
      "release_version": "s – BC-FES-JAV 7.80",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 6.0",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 6,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-0056",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP GUI for Java, Versions – BC-FES-JAV 7.80 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3502459 in its 2025-01 Security Patch Day release for SAP GUI for Java, Versions – BC-FES-JAV 7.80. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-0056"
        ],
        "details": [
          {
            "id": "CVE-2025-0056",
            "title": "Information Disclosure vulnerability in SAP GUI for Java",
            "summary": "SAP GUI for Java saves user input on the client PC to improve usability. An attacker with administrative privileges or access to the victim�s user directory on the Operating System level would be able to read this data. Depending on the user input provided in transactions, the disclosed data could range from non-critical data to highly sensitive data, causing high impact on confidentiality of the application.",
            "score": 6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00199,
            "epssPercentile": 0.09714,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-01-3503138",
      "slug": "sap-2025-01-3503138",
      "cycle_id": "2025-01",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3503138",
      "title": "Assess and apply SAP security advisory 3503138",
      "source_title": "[CVE-2025-0059] Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP (applications based on SAP GUI for HTML) | Product- SAP NetWeaver Application Server ABAP (applications based on SAP GUI for HTML), Versions – KRNL64UC 7.53, KERNEL 7.53, 7.54, 7.77, 7.89, 7.93, 9.12, 9.14",
      "source_url": "https://me.sap.com/notes/3503138",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "SAP NetWeaver Application Server ABAP (applications based on SAP GUI for HTML), Versions – KRNL64UC 7.53, KERNEL 7.53, 7.54, 7.77, 7.89, 7.93, 9.12, 9.14",
      "platform": "SAP",
      "release_version": "s – KRNL64UC 7.53, KERNEL 7.53, 7.54, 7.77, 7.89, 7.93, 9.12, 9.14",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 6.0",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 6,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-0059",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP NetWeaver Application Server ABAP (applications based on SAP GUI for HTML), Versions – KRNL64UC 7.53, KERNEL 7.53, 7.54, 7.77, 7.89, 7.93, 9.12, 9.14 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3503138 in its 2025-01 Security Patch Day release for SAP NetWeaver Application Server ABAP (applications based on SAP GUI for HTML), Versions – KRNL64UC 7.53, KERNEL 7.53, 7.54, 7.77, 7.89, 7.93, 9.12, 9.14. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-0059"
        ],
        "details": [
          {
            "id": "CVE-2025-0059",
            "title": "Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP (applications based on SAP GUI for HTML)",
            "summary": "Applications based on SAP GUI for HTML in SAP NetWeaver Application Server ABAP store user input in the local browser storage to improve usability. An attacker with administrative privileges or access to the victim�s user directory on the Operating System level would be able to read this data. Depending on the user input provided in transactions, the disclosed data could range from non-critical data to highly sensiti",
            "score": 6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00185,
            "epssPercentile": 0.08162,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-01-3514421",
      "slug": "sap-2025-01-3514421",
      "cycle_id": "2025-01",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3514421",
      "title": "Assess and apply SAP security advisory 3514421",
      "source_title": "[CVE-2025-0057] Cross-Site Scripting vulnerability in SAP NetWeaver AS JAVA (User Admin Application) | Product - SAP NetWeaver AS JAVA (User Admin Application), Version - ENGINEAPI 7.50, SERVERCORE 7.50, UMEADMIN 7.50",
      "source_url": "https://me.sap.com/notes/3514421",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "SAP NetWeaver AS JAVA (User Admin Application), Version - ENGINEAPI 7.50, SERVERCORE 7.50, UMEADMIN 7.50",
      "platform": "SAP",
      "release_version": "ENGINEAPI 7.50, SERVERCORE 7.50, UMEADMIN 7.50",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 4.8",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 4.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-0057",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP NetWeaver AS JAVA (User Admin Application), Version - ENGINEAPI 7.50, SERVERCORE 7.50, UMEADMIN 7.50 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3514421 in its 2025-01 Security Patch Day release for SAP NetWeaver AS JAVA (User Admin Application), Version - ENGINEAPI 7.50, SERVERCORE 7.50, UMEADMIN 7.50. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-0057"
        ],
        "details": [
          {
            "id": "CVE-2025-0057",
            "title": "Cross-Site Scripting vulnerability in SAP NetWeaver AS JAVA (User Admin Application)",
            "summary": "SAP NetWeaver AS JAVA (User Admin Application) is vulnerable to stored cross site scripting vulnerability. An attacker posing as an admin can upload a photo with malicious JS content. When a victim visits the vulnerable component, the attacker can read and modify information within the scope of victim's web browser.",
            "score": 4.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00239,
            "epssPercentile": 0.14898,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-01-3536461",
      "slug": "sap-2025-01-3536461",
      "cycle_id": "2025-01",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3536461",
      "title": "Assess and apply SAP security advisory 3536461",
      "source_title": "[CVE-2025-0053] Information Disclosure Vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform Product- SAP NetWeaver Application Server for ABAP and ABAP Platform, Version – SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757",
      "source_url": "https://me.sap.com/notes/3536461",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "SAP NetWeaver Application Server for ABAP and ABAP Platform, Version – SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757",
      "platform": "SAP",
      "release_version": "SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 5.3",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 5.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-0053",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP NetWeaver Application Server for ABAP and ABAP Platform, Version – SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3536461 in its 2025-01 Security Patch Day release for SAP NetWeaver Application Server for ABAP and ABAP Platform, Version – SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-0053"
        ],
        "details": [
          {
            "id": "CVE-2025-0053",
            "title": "Information Disclosure Vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform",
            "summary": "SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to gain unauthorized access to system information. By using a specific URL parameter, an unauthenticated attacker could retrieve details such as system configuration. This has a limited impact on the confidentiality of the application and may be leveraged to facilitate further attacks or exploits.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00337,
            "epssPercentile": 0.26596,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-01-3537476",
      "slug": "sap-2025-01-3537476",
      "cycle_id": "2025-01",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3537476",
      "title": "Assess and apply SAP security advisory 3537476",
      "source_title": "[CVE-2025-0070] Improper Authentication in SAP NetWeaver ABAP Server and ABAP Platform Product- SAP NetWeaver Application Server for ABAP and ABAP Platform, Versions – KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, 8.04, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 7.97, 8.04, 9.12, 9.13, 9.14",
      "source_url": "https://me.sap.com/notes/3537476",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "SAP NetWeaver Application Server for ABAP and ABAP Platform, Versions – KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, 8.04, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 7.97, 8.04, 9.12, 9.13, 9.14",
      "platform": "SAP",
      "release_version": "s – KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, 8.04, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 7.97, 8.04, 9.12, 9.13, 9.14",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 9.9",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.9,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-0070",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP NetWeaver Application Server for ABAP and ABAP Platform, Versions – KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, 8.04, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 7.97, 8.04, 9.12, 9.13, 9.14 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3537476 in its 2025-01 Security Patch Day release for SAP NetWeaver Application Server for ABAP and ABAP Platform, Versions – KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, 8.04, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 7.97, 8.04, 9.12, 9.13, 9.14. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-0070"
        ],
        "details": [
          {
            "id": "CVE-2025-0070",
            "title": "Improper Authentication in SAP NetWeaver ABAP Server and ABAP Platform",
            "summary": "SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to obtain illegitimate access to the system by exploiting improper authentication checks, resulting in privilege escalation. On successful exploitation, this can result in potential security concerns. This results in a high impact on confidentiality, integrity, and availability.",
            "score": 9.9,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00701,
            "epssPercentile": 0.50901,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-01-3540108",
      "slug": "sap-2025-01-3540108",
      "cycle_id": "2025-01",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3540108",
      "title": "Assess and apply SAP security advisory 3540108",
      "source_title": "[CVE-2025-0067] Missing Authorization check in SAP NetWeaver Application Server Java Product- SAP NetWeaver Application Server Java, Version – WD-RUNTIME 7.50",
      "source_url": "https://me.sap.com/notes/3540108",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "SAP NetWeaver Application Server Java, Version – WD-RUNTIME 7.50",
      "platform": "SAP",
      "release_version": "WD-RUNTIME 7.50",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 6.3",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 6.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-0067",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP NetWeaver Application Server Java, Version – WD-RUNTIME 7.50 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3540108 in its 2025-01 Security Patch Day release for SAP NetWeaver Application Server Java, Version – WD-RUNTIME 7.50. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-0067"
        ],
        "details": [
          {
            "id": "CVE-2025-0067",
            "title": "Missing Authorization check in SAP NetWeaver Application Server Java",
            "summary": "Due to a missing authorization check on service endpoints in the SAP NetWeaver Application Server Java, an attacker with standard user role can create JCo connection entries, which are used for remote function calls from or to the application server. This could lead to low impact on confidentiality, integrity, and availability of the application.",
            "score": 6.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00257,
            "epssPercentile": 0.17261,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-01-3542533",
      "slug": "sap-2025-01-3542533",
      "cycle_id": "2025-01",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3542533",
      "title": "Assess and apply SAP security advisory 3542533",
      "source_title": "[CVE-2025-0069] DLL Hijacking vulnerability in SAPSetup Product- SAPSetup, Version – LMSAPSETUP 9.0",
      "source_url": "https://me.sap.com/notes/3542533",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "SAPSetup, Version – LMSAPSETUP 9.0",
      "platform": "SAP",
      "release_version": "LMSAPSETUP 9.0",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "High; CVSS 7.8",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-0069",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAPSetup, Version – LMSAPSETUP 9.0 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3542533 in its 2025-01 Security Patch Day release for SAPSetup, Version – LMSAPSETUP 9.0. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-0069"
        ],
        "details": [
          {
            "id": "CVE-2025-0069",
            "title": "DLL Hijacking vulnerability in SAPSetup",
            "summary": "Due to DLL injection vulnerability in SAPSetup, an attacker with either local user privileges or with access to a compromised corporate user�s Windows account could gain higher privileges. With this, he could move laterally within the network and further compromise the active directory of a company. This leads to high impact on confidentiality, integrity and availability of the Windows server.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00178,
            "epssPercentile": 0.07465,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-01-3542698",
      "slug": "sap-2025-01-3542698",
      "cycle_id": "2025-01",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3542698",
      "title": "Assess and apply SAP security advisory 3542698",
      "source_title": "[CVE-2025-0058] Information Disclosure vulnerability in SAP Business Workflow and SAP Flexible Workflow | Product - SAP Business Workflow and SAP Flexible Workflow, Version – SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 912, SAP_BASIS 913, SAP_BASIS 914",
      "source_url": "https://me.sap.com/notes/3542698",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "SAP Business Workflow and SAP Flexible Workflow, Version – SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 912, SAP_BASIS 913, SAP_BASIS 914",
      "platform": "SAP",
      "release_version": "SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 912, SAP_BASIS 913, SAP_BASIS 914",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 6.5",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 6.5,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-0058",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP Business Workflow and SAP Flexible Workflow, Version – SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 912, SAP_BASIS 913, SAP_BASIS 914 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3542698 in its 2025-01 Security Patch Day release for SAP Business Workflow and SAP Flexible Workflow, Version – SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 912, SAP_BASIS 913, SAP_BASIS 914. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-0058"
        ],
        "details": [
          {
            "id": "CVE-2025-0058",
            "title": "Information Disclosure vulnerability in SAP Business Workflow and SAP Flexible Workflow",
            "summary": "In SAP Business Workflow and SAP Flexible Workflow, an authenticated attacker can manipulate a parameter in an otherwise legitimate resource request to view sensitive information that should otherwise be restricted. The attacker does not have the ability to modify the information or to make the information unavailable.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00336,
            "epssPercentile": 0.26432,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-01-3550674",
      "slug": "sap-2025-01-3550674",
      "cycle_id": "2025-01",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3550674",
      "title": "Assess and apply SAP security advisory 3550674",
      "source_title": "[CVE-2025-0068] Missing Authorization check in Remote Function Call (RFC) in SAP NetWeaver Application Server ABAP | Product - SAP NetWeaver Application Server ABAP, Versions - SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758",
      "source_url": "https://me.sap.com/notes/3550674",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "SAP NetWeaver Application Server ABAP, Versions - SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758",
      "platform": "SAP",
      "release_version": "s - SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 4.3",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 4.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-0068",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP NetWeaver Application Server ABAP, Versions - SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3550674 in its 2025-01 Security Patch Day release for SAP NetWeaver Application Server ABAP, Versions - SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-0068"
        ],
        "details": [
          {
            "id": "CVE-2025-0068",
            "title": "Missing Authorization check in Remote Function Call (RFC) in SAP NetWeaver Application Server ABAP",
            "summary": "An obsolete functionality in SAP NetWeaver Application Server ABAP did not perform necessary authorization checks. Because of this, an authenticated attacker could obtain information that would otherwise be restricted. It has no impact on integrity or availability on the application.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00271,
            "epssPercentile": 0.19036,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-01-3550708",
      "slug": "sap-2025-01-3550708",
      "cycle_id": "2025-01",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3550708",
      "title": "Assess and apply SAP security advisory 3550708",
      "source_title": "[CVE-2025-0066] Information Disclosure vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform(Internet Communication Framework) Product- SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework), Versions – SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 912, SAP_BASIS 913, SAP_BASIS 914",
      "source_url": "https://me.sap.com/notes/3550708",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework), Versions – SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 912, SAP_BASIS 913, SAP_BASIS 914",
      "platform": "SAP",
      "release_version": "s – SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 912, SAP_BASIS 913, SAP_BASIS 914",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 9.9",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.9,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-0066",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework), Versions – SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 912, SAP_BASIS 913, SAP_BASIS 914 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3550708 in its 2025-01 Security Patch Day release for SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework), Versions – SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 912, SAP_BASIS 913, SAP_BASIS 914. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-0066"
        ],
        "details": [
          {
            "id": "CVE-2025-0066",
            "title": "Information Disclosure vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework)",
            "summary": "Under certain conditions SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework) allows an attacker to access restricted information due to weak access controls. This can have a significant impact on the confidentiality, integrity, and availability of an application",
            "score": 9.9,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00579,
            "epssPercentile": 0.45511,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-01-3550816",
      "slug": "sap-2025-01-3550816",
      "cycle_id": "2025-01",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3550816",
      "title": "Assess and apply SAP security advisory 3550816",
      "source_title": "[CVE-2025-0063] SQL Injection vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform Product – SAP NetWeaver AS ABAP and ABAP Platform, Version – SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758",
      "source_url": "https://me.sap.com/notes/3550816",
      "published_at": "2025-01-14",
      "updated_at": "2025-01-14",
      "status": "active",
      "product": "SAP NetWeaver AS ABAP and ABAP Platform, Version – SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758",
      "platform": "SAP",
      "release_version": "SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "High; CVSS 8.8",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-0063",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP NetWeaver AS ABAP and ABAP Platform, Version – SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3550816 in its 2025-01 Security Patch Day release for SAP NetWeaver AS ABAP and ABAP Platform, Version – SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-0063"
        ],
        "details": [
          {
            "id": "CVE-2025-0063",
            "title": "SQL Injection vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform",
            "summary": "SAP NetWeaver AS ABAP and ABAP Platform does not check for authorization when a user executes some RFC function modules. This could lead to an attacker with basic user privileges to gain control over the data in Informix database, leading to complete compromise of confidentiality, integrity and availability.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00745,
            "epssPercentile": 0.52439,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:30Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-01-14",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "adobe-apsb25-08",
      "slug": "adobe-apsb25-08",
      "cycle_id": "2025-02",
      "vendor_id": "adobe",
      "vendor_name": "Adobe",
      "source_id": "adobe-security-bulletins",
      "advisory_id": "APSB25-08",
      "title": "Update Adobe Commerce to the fixed Adobe release",
      "source_title": "APSB25-08 : Security update available for Adobe Commerce",
      "source_url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Adobe Commerce",
      "platform": "All",
      "release_version": "2.4.8-beta2 for 2.4.8-beta1, 2.4.7-p4 for 2.4.7-p3 and earlier, 2.4.6-p9 for 2.4.6-p8 and earlier, 2.4.5-p11 for 2.4.5-p10 and earlier, 2.4.4-p12 for 2.4.4-p11 and earlier, Isolated patch for CVE-2025-24434",
      "action_type": "upgrade-release",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 9.4; Adobe priority 2, 1",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-24434",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Adobe Commerce exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "Adobe published APSB25-08 on Patch Tuesday for Adobe Commerce. The bulletin links 31 CVEs and provides fixed release guidance.",
      "cves": {
        "state": "complete-for-advisory",
        "vendor_stated_count": 31,
        "ids": [
          "CVE-2025-24406",
          "CVE-2025-24407",
          "CVE-2025-24408",
          "CVE-2025-24409",
          "CVE-2025-24410",
          "CVE-2025-24411",
          "CVE-2025-24412",
          "CVE-2025-24413",
          "CVE-2025-24414",
          "CVE-2025-24415",
          "CVE-2025-24416",
          "CVE-2025-24417",
          "CVE-2025-24418",
          "CVE-2025-24419",
          "CVE-2025-24420",
          "CVE-2025-24421",
          "CVE-2025-24422",
          "CVE-2025-24423",
          "CVE-2025-24424",
          "CVE-2025-24425",
          "CVE-2025-24426",
          "CVE-2025-24427",
          "CVE-2025-24428",
          "CVE-2025-24429",
          "CVE-2025-24430",
          "CVE-2025-24432",
          "CVE-2025-24434",
          "CVE-2025-24435",
          "CVE-2025-24436",
          "CVE-2025-24437",
          "CVE-2025-24438"
        ],
        "details": [
          {
            "id": "CVE-2025-24406",
            "title": "Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)",
            "summary": "Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to a security feature bypass. An unauthenticated attacker could exploit this vulnerability to modify files that are stored outside the restricted directory. Exploitation of this issue does not require u",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01395,
            "epssPercentile": 0.70592,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24407",
            "title": "Adobe Commerce | Incorrect Authorization (CWE-863)",
            "summary": "Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low privileged attacker could exploit this vulnerability to perform actions with permissions that were not granted leading to both a High impact to confidentiality and Low impact to integrity. Exploitation of this issue doe",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00787,
            "epssPercentile": 0.53797,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24408",
            "title": "Adobe Commerce | Information Exposure (CWE-200)",
            "summary": "Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Information Exposure vulnerability that could result in privilege escalation. A low-privileged attacker could gain unauthorized access to sensitive information. Exploitation of this issue does not require user interaction.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00953,
            "epssPercentile": 0.5904,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24409",
            "title": "Adobe Commerce | Incorrect Authorization (CWE-863)",
            "summary": "Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access, leading to both a High impact to confidentiality and Low impact to integrity. Exploitation of this issue does not require",
            "score": 8.2,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00679,
            "epssPercentile": 0.50064,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24410",
            "title": "Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)",
            "summary": "Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can abuse this",
            "score": 8.7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00704,
            "epssPercentile": 0.51,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24411",
            "title": "Adobe Commerce | Improper Access Control (CWE-284)",
            "summary": "Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized access affecting Confidentiality and Integrity. Exploitation of this issue does not require user interaction.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00914,
            "epssPercentile": 0.57808,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24412",
            "title": "Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)",
            "summary": "Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can abuse this",
            "score": 8.7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00704,
            "epssPercentile": 0.50999,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24413",
            "title": "Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)",
            "summary": "Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can abuse this",
            "score": 8.7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00704,
            "epssPercentile": 0.51,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24414",
            "title": "Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)",
            "summary": "Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can abuse this",
            "score": 8.7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00704,
            "epssPercentile": 0.51001,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24415",
            "title": "Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)",
            "summary": "Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can abuse this",
            "score": 8.7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00704,
            "epssPercentile": 0.51,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24416",
            "title": "Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)",
            "summary": "Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can abuse this",
            "score": 8.7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00704,
            "epssPercentile": 0.51001,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24417",
            "title": "Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)",
            "summary": "Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can abuse this",
            "score": 8.7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00704,
            "epssPercentile": 0.51001,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24418",
            "title": "Adobe Commerce | Improper Authorization (CWE-285)",
            "summary": "Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00958,
            "epssPercentile": 0.59183,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24419",
            "title": "Adobe Commerce | Incorrect Authorization (CWE-863)",
            "summary": "Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to modify select data. Exploitation of this issue does not require user interaction.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00557,
            "epssPercentile": 0.44385,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24420",
            "title": "Adobe Commerce | Incorrect Authorization (CWE-863)",
            "summary": "Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to modify select data. Exploitation of this issue does not require user interaction.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00557,
            "epssPercentile": 0.44386,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24421",
            "title": "Adobe Commerce | Incorrect Authorization (CWE-863)",
            "summary": "Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to read select data. Exploitation of this issue does not require user interaction",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00547,
            "epssPercentile": 0.43884,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24422",
            "title": "Adobe Commerce | Improper Access Control (CWE-284)",
            "summary": "Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00766,
            "epssPercentile": 0.53166,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24423",
            "title": "Adobe Commerce | Improper Access Control (CWE-284)",
            "summary": "Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in Privilege escalation. A low-privileged attacker could leverage this vulnerability to modify select data. Exploitation of this issue does not require user interaction.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0052,
            "epssPercentile": 0.42337,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24424",
            "title": "Adobe Commerce | Improper Access Control (CWE-284)",
            "summary": "Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00766,
            "epssPercentile": 0.53165,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24425",
            "title": "Adobe Commerce | Business Logic Errors (CWE-840)",
            "summary": "Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Business Logic Error vulnerability that could result in a security feature bypass. An attacker could exploit this vulnerability to circumvent intended security mechanisms by manipulating the logic of the application's operations causing limited data modification. Exploitation of this issue does not require user",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00634,
            "epssPercentile": 0.48123,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24426",
            "title": "Adobe Commerce | Improper Access Control (CWE-284)",
            "summary": "Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00766,
            "epssPercentile": 0.53165,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24427",
            "title": "Adobe Commerce | Improper Access Control (CWE-284)",
            "summary": "Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00632,
            "epssPercentile": 0.48043,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24428",
            "title": "Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)",
            "summary": "Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.",
            "score": 5.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00411,
            "epssPercentile": 0.34393,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24429",
            "title": "Adobe Commerce | Improper Access Control (CWE-284)",
            "summary": "Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass allowing read only access. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue requires user interaction.",
            "score": 3.5,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00504,
            "epssPercentile": 0.41293,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24430",
            "title": "Adobe Commerce | Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367)",
            "summary": "Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass. An attacker could exploit this race condition to alter a condition after it has been checked but before it is used, potentially bypassing rate limiting mechanisms. Exploitation of this issue does not ",
            "score": 3.7,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00399,
            "epssPercentile": 0.33239,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24432",
            "title": "Adobe Commerce | Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367)",
            "summary": "Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass. An attacker could exploit this race condition to alter a condition after it has been checked but before it is used, potentially bypassing rate limiting mechanisms. Exploitation of this issue does not ",
            "score": 3.7,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00399,
            "epssPercentile": 0.33239,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24434",
            "title": "Adobe Commerce | Incorrect Authorization (CWE-863)",
            "summary": "Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction. A successful attacker can abuse this to achieve session takeover",
            "score": 9.1,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.17186,
            "epssPercentile": 0.96883,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24435",
            "title": "Adobe Commerce | Improper Access Control (CWE-284)",
            "summary": "Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in Privilege escalation. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized access to modify limited fields. Exploitation of this issue does not require user interaction.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00531,
            "epssPercentile": 0.42998,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24436",
            "title": "Adobe Commerce | Incorrect Authorization (CWE-863)",
            "summary": "Adobe Commerce versions 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11, 2.4.8-beta1 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to view select information. Exploitation of this issue does not require user interaction.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00547,
            "epssPercentile": 0.43884,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24437",
            "title": "Adobe Commerce | Incorrect Authorization (CWE-863)",
            "summary": "Adobe Commerce versions 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11, 2.4.8-beta1 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to view or modify select information. Exploitation of this issue does not require user interaction.",
            "score": 5.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00449,
            "epssPercentile": 0.37646,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24438",
            "title": "Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)",
            "summary": "Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can abuse this",
            "score": 8.7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00797,
            "epssPercentile": 0.54122,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update path and test the fixed release against managed plug-ins, workflows and file formats before broad deployment."
      ],
      "data_gaps": [
        "Restart requirements are not asserted unless the reviewed bulletin states them explicitly."
      ],
      "provenance": [
        {
          "field": "advisory_identity_and_release",
          "source_path": "adobe-bulletin/solution",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships",
          "source_path": "adobe-bulletin/vulnerability-details",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial publication of APSB25-08."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The bulletin identity, release date, fixed versions, platforms, vendor signals and complete public CVE list were generated from the official Adobe bulletin and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "adobe-apsb25-12",
      "slug": "adobe-apsb25-12",
      "cycle_id": "2025-02",
      "vendor_id": "adobe",
      "vendor_name": "Adobe",
      "source_id": "adobe-security-bulletins",
      "advisory_id": "APSB25-12",
      "title": "Update Adobe Substance 3D Designer to the fixed Adobe release",
      "source_title": "APSB25-12 : Security update available for Adobe Substance 3D Designer",
      "source_url": "https://helpx.adobe.com/security/products/substance3d_designer/apsb25-12.html",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Adobe Substance 3D Designer",
      "platform": "All",
      "release_version": "14.1",
      "action_type": "upgrade-release",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 7.8; Adobe priority 3",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21161",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Adobe Substance 3D Designer exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "Adobe published APSB25-12 on Patch Tuesday for Adobe Substance 3D Designer. The bulletin links 1 CVE and provides fixed release guidance.",
      "cves": {
        "state": "complete-for-advisory",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21161"
        ],
        "details": [
          {
            "id": "CVE-2025-21161",
            "title": "Substance3D - Designer | Out-of-bounds Write (CWE-787)",
            "summary": "Substance3D - Designer versions 14.0.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00336,
            "epssPercentile": 0.2644,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update path and test the fixed release against managed plug-ins, workflows and file formats before broad deployment."
      ],
      "data_gaps": [
        "Restart requirements are not asserted unless the reviewed bulletin states them explicitly."
      ],
      "provenance": [
        {
          "field": "advisory_identity_and_release",
          "source_path": "adobe-bulletin/solution",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships",
          "source_path": "adobe-bulletin/vulnerability-details",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial publication of APSB25-12."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The bulletin identity, release date, fixed versions, platforms, vendor signals and complete public CVE list were generated from the official Adobe bulletin and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "adobe-apsb25-01",
      "slug": "adobe-apsb25-01",
      "cycle_id": "2025-02",
      "vendor_id": "adobe",
      "vendor_name": "Adobe",
      "source_id": "adobe-security-bulletins",
      "advisory_id": "APSB25-01",
      "title": "Update Adobe InDesign to the fixed Adobe release",
      "source_title": "APSB25-01 : Security update available for Adobe InDesign",
      "source_url": "https://helpx.adobe.com/security/products/indesign/apsb25-01.html",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Adobe InDesign",
      "platform": "Windows and macOS",
      "release_version": "ID20.1, ID19.5.2",
      "action_type": "upgrade-release",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 7.8; Adobe priority 3",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21158",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Adobe InDesign exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "Adobe published APSB25-01 on Patch Tuesday for Adobe InDesign. The bulletin links 7 CVEs and provides fixed release guidance.",
      "cves": {
        "state": "complete-for-advisory",
        "vendor_stated_count": 7,
        "ids": [
          "CVE-2025-21121",
          "CVE-2025-21123",
          "CVE-2025-21124",
          "CVE-2025-21125",
          "CVE-2025-21126",
          "CVE-2025-21157",
          "CVE-2025-21158"
        ],
        "details": [
          {
            "id": "CVE-2025-21121",
            "title": "InDesign Desktop | Out-of-bounds Write (CWE-787)",
            "summary": "InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00267,
            "epssPercentile": 0.18668,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21123",
            "title": "InDesign Desktop | Heap-based Buffer Overflow (CWE-122)",
            "summary": "InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00346,
            "epssPercentile": 0.27561,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21124",
            "title": "InDesign Desktop | Out-of-bounds Read (CWE-125)",
            "summary": "InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00294,
            "epssPercentile": 0.21663,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21125",
            "title": "InDesign Desktop | NULL Pointer Dereference (CWE-476)",
            "summary": "InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00261,
            "epssPercentile": 0.17764,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21126",
            "title": "InDesign Desktop | Improper Input Validation (CWE-20)",
            "summary": "InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service condition. An attacker could exploit this vulnerability to cause the application to crash, resulting in a denial of service. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00255,
            "epssPercentile": 0.1696,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21157",
            "title": "InDesign Desktop | Out-of-bounds Write (CWE-787)",
            "summary": "InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00284,
            "epssPercentile": 0.20608,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21158",
            "title": "InDesign Desktop | Integer Underflow (Wrap or Wraparound) (CWE-191)",
            "summary": "InDesign Desktop versions ID20.0, ID19.5.1 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00314,
            "epssPercentile": 0.23945,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update path and test the fixed release against managed plug-ins, workflows and file formats before broad deployment."
      ],
      "data_gaps": [
        "Restart requirements are not asserted unless the reviewed bulletin states them explicitly."
      ],
      "provenance": [
        {
          "field": "advisory_identity_and_release",
          "source_path": "adobe-bulletin/solution",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships",
          "source_path": "adobe-bulletin/vulnerability-details",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial publication of APSB25-01."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The bulletin identity, release date, fixed versions, platforms, vendor signals and complete public CVE list were generated from the official Adobe bulletin and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "adobe-apsb25-09",
      "slug": "adobe-apsb25-09",
      "cycle_id": "2025-02",
      "vendor_id": "adobe",
      "vendor_name": "Adobe",
      "source_id": "adobe-security-bulletins",
      "advisory_id": "APSB25-09",
      "title": "Update Adobe Substance 3D Stager to the fixed Adobe release",
      "source_title": "APSB25-09 : Security update available for Adobe Substance 3D Stager",
      "source_url": "https://helpx.adobe.com/security/products/substance3d_stager/apsb25-09.html",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Adobe Substance 3D Stager",
      "platform": "Windows and macOS",
      "release_version": "3.1.1",
      "action_type": "upgrade-release",
      "restart_required": "unknown",
      "vendor_severity": "Important; CVSS 5.5; Adobe priority 3",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 5.5,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21155",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Adobe Substance 3D Stager exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "Adobe published APSB25-09 on Patch Tuesday for Adobe Substance 3D Stager. The bulletin links 1 CVE and provides fixed release guidance.",
      "cves": {
        "state": "complete-for-advisory",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21155"
        ],
        "details": [
          {
            "id": "CVE-2025-21155",
            "title": "Substance3D - Stager | NULL Pointer Dereference (CWE-476)",
            "summary": "Substance3D - Stager versions 3.1.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00281,
            "epssPercentile": 0.20281,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update path and test the fixed release against managed plug-ins, workflows and file formats before broad deployment."
      ],
      "data_gaps": [
        "Restart requirements are not asserted unless the reviewed bulletin states them explicitly."
      ],
      "provenance": [
        {
          "field": "advisory_identity_and_release",
          "source_path": "adobe-bulletin/solution",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships",
          "source_path": "adobe-bulletin/vulnerability-details",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial publication of APSB25-09."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The bulletin identity, release date, fixed versions, platforms, vendor signals and complete public CVE list were generated from the official Adobe bulletin and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "adobe-apsb25-10",
      "slug": "adobe-apsb25-10",
      "cycle_id": "2025-02",
      "vendor_id": "adobe",
      "vendor_name": "Adobe",
      "source_id": "adobe-security-bulletins",
      "advisory_id": "APSB25-10",
      "title": "Update Adobe InCopy to the fixed Adobe release",
      "source_title": "APSB25-10 : Security update available for Adobe InCopy",
      "source_url": "https://helpx.adobe.com/security/products/incopy/apsb25-10.html",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Adobe InCopy",
      "platform": "Windows and macOS",
      "release_version": "20.1, 19.5.2",
      "action_type": "upgrade-release",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 7.8; Adobe priority 3",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21156",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Adobe InCopy exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "Adobe published APSB25-10 on Patch Tuesday for Adobe InCopy. The bulletin links 1 CVE and provides fixed release guidance.",
      "cves": {
        "state": "complete-for-advisory",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21156"
        ],
        "details": [
          {
            "id": "CVE-2025-21156",
            "title": "InCopy | Integer Underflow (Wrap or Wraparound) (CWE-191)",
            "summary": "InCopy versions 20.0, 19.5.1 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00338,
            "epssPercentile": 0.26616,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update path and test the fixed release against managed plug-ins, workflows and file formats before broad deployment."
      ],
      "data_gaps": [
        "Restart requirements are not asserted unless the reviewed bulletin states them explicitly."
      ],
      "provenance": [
        {
          "field": "advisory_identity_and_release",
          "source_path": "adobe-bulletin/solution",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships",
          "source_path": "adobe-bulletin/vulnerability-details",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial publication of APSB25-10."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The bulletin identity, release date, fixed versions, platforms, vendor signals and complete public CVE list were generated from the official Adobe bulletin and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "adobe-apsb25-11",
      "slug": "adobe-apsb25-11",
      "cycle_id": "2025-02",
      "vendor_id": "adobe",
      "vendor_name": "Adobe",
      "source_id": "adobe-security-bulletins",
      "advisory_id": "APSB25-11",
      "title": "Update Adobe Illustrator to the fixed Adobe release",
      "source_title": "APSB25-11 : Security update available for Adobe Illustrator",
      "source_url": "https://helpx.adobe.com/security/products/illustrator/apsb25-11.html",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Adobe Illustrator",
      "platform": "Windows and macOS",
      "release_version": "29.2.1 and above, 28.7.4 and above",
      "action_type": "upgrade-release",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 7.8; Adobe priority 3",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21163",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Adobe Illustrator exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "Adobe published APSB25-11 on Patch Tuesday for Adobe Illustrator. The bulletin links 3 CVEs and provides fixed release guidance.",
      "cves": {
        "state": "complete-for-advisory",
        "vendor_stated_count": 3,
        "ids": [
          "CVE-2025-21159",
          "CVE-2025-21160",
          "CVE-2025-21163"
        ],
        "details": [
          {
            "id": "CVE-2025-21159",
            "title": "Illustrator | Use After Free (CWE-416)",
            "summary": "Illustrator versions 29.1, 28.7.3 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00404,
            "epssPercentile": 0.33737,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21160",
            "title": "Illustrator | Integer Underflow (Wrap or Wraparound) (CWE-191)",
            "summary": "Illustrator versions 29.1, 28.7.3 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00368,
            "epssPercentile": 0.2991,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21163",
            "title": "Illustrator | Stack-based Buffer Overflow (CWE-121)",
            "summary": "Illustrator versions 29.1, 28.7.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00374,
            "epssPercentile": 0.30559,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update path and test the fixed release against managed plug-ins, workflows and file formats before broad deployment."
      ],
      "data_gaps": [
        "Restart requirements are not asserted unless the reviewed bulletin states them explicitly."
      ],
      "provenance": [
        {
          "field": "advisory_identity_and_release",
          "source_path": "adobe-bulletin/solution",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships",
          "source_path": "adobe-bulletin/vulnerability-details",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial publication of APSB25-11."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The bulletin identity, release date, fixed versions, platforms, vendor signals and complete public CVE list were generated from the official Adobe bulletin and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "adobe-apsb25-13",
      "slug": "adobe-apsb25-13",
      "cycle_id": "2025-02",
      "vendor_id": "adobe",
      "vendor_name": "Adobe",
      "source_id": "adobe-security-bulletins",
      "advisory_id": "APSB25-13",
      "title": "Update Adobe Photoshop Elements to the fixed Adobe release",
      "source_title": "APSB25-13 : Security update available for Adobe Photoshop Elements",
      "source_url": "https://helpx.adobe.com/security/products/photoshop_elements/apsb25-13.html",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Adobe Photoshop Elements",
      "platform": "macOS (ARM)",
      "release_version": "2025.1 [build: 20250124.PSE.f552973b, 20250124.PSE.5345f07d (Mac ARM)]",
      "action_type": "upgrade-release",
      "restart_required": "unknown",
      "vendor_severity": "Important; CVSS 5.0; Adobe priority 3",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 5.5,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21162",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Adobe Photoshop Elements exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "Adobe published APSB25-13 on Patch Tuesday for Adobe Photoshop Elements. The bulletin links 1 CVE and provides fixed release guidance.",
      "cves": {
        "state": "complete-for-advisory",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21162"
        ],
        "details": [
          {
            "id": "CVE-2025-21162",
            "title": "Photoshop Elements | Creation of Temporary File in Directory with Incorrect Permissions (CWE-379)",
            "summary": "Photoshop Elements versions 2025.0 and earlier are affected by a Creation of Temporary File in Directory with Incorrect Permissions vulnerability that could result in privilege escalation in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00311,
            "epssPercentile": 0.23507,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update path and test the fixed release against managed plug-ins, workflows and file formats before broad deployment."
      ],
      "data_gaps": [
        "Restart requirements are not asserted unless the reviewed bulletin states them explicitly."
      ],
      "provenance": [
        {
          "field": "advisory_identity_and_release",
          "source_path": "adobe-bulletin/solution",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships",
          "source_path": "adobe-bulletin/vulnerability-details",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial publication of APSB25-13."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The bulletin identity, release date, fixed versions, platforms, vendor signals and complete public CVE list were generated from the official Adobe bulletin and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-apps-msrc-2025-02-apps-release-notes-microsoft-outlook-for-android",
      "slug": "microsoft-2025-02-apps-msrc-2025-02-apps-release-notes-microsoft-outlook-for-android",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-02-apps-release-notes",
      "title": "Deploy Microsoft Apps update for Microsoft Outlook for Android",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://play.google.com/store/apps/details/Microsoft_Outlook?id=com.microsoft.office.outlook&hl=en_US&pli=1",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Microsoft Outlook for Android",
      "platform": "Apps",
      "release_version": "4.2501.1",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 5.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21259",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Outlook for Android exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Outlook for Android.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21259"
        ],
        "details": [
          {
            "id": "CVE-2025-21259",
            "title": "Microsoft Outlook Spoofing Vulnerability",
            "summary": "Microsoft Outlook Spoofing Vulnerability",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01164,
            "epssPercentile": 0.65198,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-apps-msrc-2025-02-apps-release-notes-microsoft-pc-manager",
      "slug": "microsoft-2025-02-apps-msrc-2025-02-apps-release-notes-microsoft-pc-manager",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-02-apps-release-notes",
      "title": "Deploy Microsoft Apps update for Microsoft PC Manager",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://apps.microsoft.com/detail/9pm860492szd?hl=en-us&gl=US",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Microsoft PC Manager",
      "platform": "Apps",
      "release_version": "3.15.4.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21322",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft PC Manager exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft PC Manager.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21322"
        ],
        "details": [
          {
            "id": "CVE-2025-21322",
            "title": "Microsoft PC Manager Elevation of Privilege Vulnerability",
            "summary": "Microsoft PC Manager Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00686,
            "epssPercentile": 0.50366,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-azure-msrc-2025-02-azure-release-notes-azure-network-watcher-vm-extension",
      "slug": "microsoft-2025-02-azure-msrc-2025-02-azure-release-notes-azure-network-watcher-vm-extension",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-02-azure-release-notes",
      "title": "Deploy Microsoft Azure update for Azure Network Watcher VM Extension",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://learn.microsoft.com/en-us/azure/virtual-machines/extensions/network-watcher-update?tabs=windows",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Azure Network Watcher VM Extension",
      "platform": "Azure",
      "release_version": "1.4.3563.1",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 6,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21188",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Azure Network Watcher VM Extension exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Network Watcher VM Extension.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21188"
        ],
        "details": [
          {
            "id": "CVE-2025-21188",
            "title": "Azure Network Watcher VM Extension Elevation of Privilege Vulnerability",
            "summary": "Azure Network Watcher VM Extension Elevation of Privilege Vulnerability",
            "score": 6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00711,
            "epssPercentile": 0.5126,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-azure-msrc-2025-02-azure-release-notes-microsoft-hpc-pack-2019",
      "slug": "microsoft-2025-02-azure-msrc-2025-02-azure-release-notes-microsoft-hpc-pack-2019",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-02-azure-release-notes",
      "title": "Deploy Microsoft Azure update for Microsoft HPC Pack 2019",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://go.microsoft.com/fwlink/?linkid=2303840",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Microsoft HPC Pack 2019",
      "platform": "Azure",
      "release_version": "6.3.8328.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21198",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft HPC Pack 2019 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft HPC Pack 2019.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21198"
        ],
        "details": [
          {
            "id": "CVE-2025-21198",
            "title": "Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability",
            "summary": "Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability",
            "score": 9,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00939,
            "epssPercentile": 0.58621,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-azure-msrc-2025-02-azure-release-notes-microsoft-hpc-pack-2016",
      "slug": "microsoft-2025-02-azure-msrc-2025-02-azure-release-notes-microsoft-hpc-pack-2016",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-02-azure-release-notes",
      "title": "Deploy Microsoft Azure update for Microsoft HPC Pack 2016",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://go.microsoft.com/fwlink/?linkid=2303840",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Microsoft HPC Pack 2016",
      "platform": "Azure",
      "release_version": "2016.3",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21198",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft HPC Pack 2016 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft HPC Pack 2016.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21198"
        ],
        "details": [
          {
            "id": "CVE-2025-21198",
            "title": "Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability",
            "summary": "Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability",
            "score": 9,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00939,
            "epssPercentile": 0.58621,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "Critical technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-developer-tools-msrc-2025-02-developer-tools-release-notes-microsoft-visual-studio-2017-version-15-9-includes-15-0-15-8",
      "slug": "microsoft-2025-02-developer-tools-msrc-2025-02-developer-tools-release-notes-microsoft-visual-studio-2017-version-15-9-includes-15-0-15-8",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-02-developer-tools-release-notes",
      "title": "Deploy Microsoft Developer Tools update for Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://aka.ms/vs/15/release/latest",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)",
      "platform": "Developer Tools",
      "release_version": "15.9.70",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21206",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21206"
        ],
        "details": [
          {
            "id": "CVE-2025-21206",
            "title": "Visual Studio Installer Elevation of Privilege Vulnerability",
            "summary": "Visual Studio Installer Elevation of Privilege Vulnerability",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00695,
            "epssPercentile": 0.50685,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-developer-tools-msrc-2025-02-developer-tools-release-notes-microsoft-visual-studio-2019-version-16-11-includes-16-0-16-10",
      "slug": "microsoft-2025-02-developer-tools-msrc-2025-02-developer-tools-release-notes-microsoft-visual-studio-2019-version-16-11-includes-16-0-16-10",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-02-developer-tools-release-notes",
      "title": "Deploy Microsoft Developer Tools update for Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://my.visualstudio.com/Downloads?q=Visual Studio 2019 version 16.11",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)",
      "platform": "Developer Tools",
      "release_version": "16.11.44",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21206",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21206"
        ],
        "details": [
          {
            "id": "CVE-2025-21206",
            "title": "Visual Studio Installer Elevation of Privilege Vulnerability",
            "summary": "Visual Studio Installer Elevation of Privilege Vulnerability",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00695,
            "epssPercentile": 0.50685,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-developer-tools-msrc-2025-02-developer-tools-release-notes-microsoft-visual-studio-2022-version-17-8",
      "slug": "microsoft-2025-02-developer-tools-msrc-2025-02-developer-tools-release-notes-microsoft-visual-studio-2022-version-17-8",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-02-developer-tools-release-notes",
      "title": "Deploy Microsoft Developer Tools update for Microsoft Visual Studio 2022 version 17.8",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.8",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Microsoft Visual Studio 2022 version 17.8",
      "platform": "Developer Tools",
      "release_version": "17.8.18",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21206",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Visual Studio 2022 version 17.8 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Visual Studio 2022 version 17.8.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21206"
        ],
        "details": [
          {
            "id": "CVE-2025-21206",
            "title": "Visual Studio Installer Elevation of Privilege Vulnerability",
            "summary": "Visual Studio Installer Elevation of Privilege Vulnerability",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00695,
            "epssPercentile": 0.50685,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-developer-tools-msrc-2025-02-developer-tools-release-notes-microsoft-visual-studio-2022-version-17-10",
      "slug": "microsoft-2025-02-developer-tools-msrc-2025-02-developer-tools-release-notes-microsoft-visual-studio-2022-version-17-10",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-02-developer-tools-release-notes",
      "title": "Deploy Microsoft Developer Tools update for Microsoft Visual Studio 2022 version 17.10",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.10",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Microsoft Visual Studio 2022 version 17.10",
      "platform": "Developer Tools",
      "release_version": "17.10.11",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21206",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Visual Studio 2022 version 17.10 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Visual Studio 2022 version 17.10.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21206"
        ],
        "details": [
          {
            "id": "CVE-2025-21206",
            "title": "Visual Studio Installer Elevation of Privilege Vulnerability",
            "summary": "Visual Studio Installer Elevation of Privilege Vulnerability",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00695,
            "epssPercentile": 0.50685,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-developer-tools-msrc-2025-02-developer-tools-release-notes-microsoft-visual-studio-2022-version-17-12",
      "slug": "microsoft-2025-02-developer-tools-msrc-2025-02-developer-tools-release-notes-microsoft-visual-studio-2022-version-17-12",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-02-developer-tools-release-notes",
      "title": "Deploy Microsoft Developer Tools update for Microsoft Visual Studio 2022 version 17.12",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.12",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Microsoft Visual Studio 2022 version 17.12",
      "platform": "Developer Tools",
      "release_version": "17.12.5",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21206",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Visual Studio 2022 version 17.12 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Visual Studio 2022 version 17.12.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21206"
        ],
        "details": [
          {
            "id": "CVE-2025-21206",
            "title": "Visual Studio Installer Elevation of Privilege Vulnerability",
            "summary": "Visual Studio Installer Elevation of Privilege Vulnerability",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00695,
            "epssPercentile": 0.50685,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-developer-tools-msrc-2025-02-developer-tools-release-notes-visual-studio-code",
      "slug": "microsoft-2025-02-developer-tools-msrc-2025-02-developer-tools-release-notes-visual-studio-code",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-02-developer-tools-release-notes",
      "title": "Deploy Microsoft Developer Tools update for Visual Studio Code",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://code.visualstudio.com/download",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Visual Studio Code",
      "platform": "Developer Tools",
      "release_version": "1.97.1",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-24039",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Visual Studio Code exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Visual Studio Code.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-24039"
        ],
        "details": [
          {
            "id": "CVE-2025-24039",
            "title": "Visual Studio Code Elevation of Privilege Vulnerability",
            "summary": "Visual Studio Code Elevation of Privilege Vulnerability",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00756,
            "epssPercentile": 0.52805,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-developer-tools-msrc-2025-02-developer-tools-release-notes-visual-studio-code-js-debug-extension",
      "slug": "microsoft-2025-02-developer-tools-msrc-2025-02-developer-tools-release-notes-visual-studio-code-js-debug-extension",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-02-developer-tools-release-notes",
      "title": "Deploy Microsoft Developer Tools update for Visual Studio Code - JS Debug Extension",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://code.visualstudio.com/download",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Visual Studio Code - JS Debug Extension",
      "platform": "Developer Tools",
      "release_version": "1.97.1",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-24042",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Visual Studio Code - JS Debug Extension exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Visual Studio Code - JS Debug Extension.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-24042"
        ],
        "details": [
          {
            "id": "CVE-2025-24042",
            "title": "Visual Studio Code JS Debug Extension Elevation of Privilege Vulnerability",
            "summary": "Visual Studio Code JS Debug Extension Elevation of Privilege Vulnerability",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00706,
            "epssPercentile": 0.51076,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-esu-kb5051972",
      "slug": "microsoft-2025-02-esu-kb5051972",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5051972",
      "title": "Deploy Microsoft ESU security update KB5051972",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5051972",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation), Windows Server 2008 for 32-bit Systems Service Pack 2, plus 7 more",
      "platform": "ESU",
      "release_version": "1",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 6.5,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21377",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation), Windows Server 2008 for 32-bit Systems Service Pack 2, plus 7 more exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation), Windows Server 2008 for 32-bit Systems Service Pack 2, plus 7 more. Microsoft marks CVE-2025-21377 as publicly disclosed, without that disclosure alone changing the BlackTree action window.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21377"
        ],
        "details": [
          {
            "id": "CVE-2025-21377",
            "title": "NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "NTLM Hash Disclosure Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.24457,
            "epssPercentile": 0.97722,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-esu-kb5051974",
      "slug": "microsoft-2025-02-esu-kb5051974",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5051974",
      "title": "Deploy Microsoft ESU security update KB5051974",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5051974",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Windows 10 Version 22H2 for 32-bit Systems, Windows 10 Version 22H2 for ARM64-based Systems, Windows 10 Version 22H2 for x64-based Systems",
      "platform": "ESU",
      "release_version": "10.0.19045.5487",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21407",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows 10 Version 22H2 for 32-bit Systems, Windows 10 Version 22H2 for ARM64-based Systems, Windows 10 Version 22H2 for x64-based Systems exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 31 linked CVEs for Windows 10 Version 22H2 for 32-bit Systems, Windows 10 Version 22H2 for ARM64-based Systems, Windows 10 Version 22H2 for x64-based Systems. Microsoft reports exploitation for CVE-2025-21391, CVE-2025-21418.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 31,
        "ids": [
          "CVE-2025-21181",
          "CVE-2025-21184",
          "CVE-2025-21190",
          "CVE-2025-21200",
          "CVE-2025-21201",
          "CVE-2025-21212",
          "CVE-2025-21216",
          "CVE-2025-21254",
          "CVE-2025-21337",
          "CVE-2025-21347",
          "CVE-2025-21349",
          "CVE-2025-21350",
          "CVE-2025-21351",
          "CVE-2025-21352",
          "CVE-2025-21358",
          "CVE-2025-21359",
          "CVE-2025-21367",
          "CVE-2025-21368",
          "CVE-2025-21369",
          "CVE-2025-21371",
          "CVE-2025-21373",
          "CVE-2025-21375",
          "CVE-2025-21376",
          "CVE-2025-21377",
          "CVE-2025-21391",
          "CVE-2025-21406",
          "CVE-2025-21407",
          "CVE-2025-21414",
          "CVE-2025-21418",
          "CVE-2025-21419",
          "CVE-2025-21420"
        ],
        "details": [
          {
            "id": "CVE-2025-21181",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03511,
            "epssPercentile": 0.88429,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21184",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0061,
            "epssPercentile": 0.46994,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21190",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21200",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21201",
            "title": "Windows Telephony Server Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Server Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21212",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0104,
            "epssPercentile": 0.61739,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21216",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0104,
            "epssPercentile": 0.61739,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21254",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01043,
            "epssPercentile": 0.61852,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21337",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Windows NTFS Elevation of Privilege Vulnerability",
            "score": 3.3,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00613,
            "epssPercentile": 0.47117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21347",
            "title": "Windows Deployment Services Denial of Service Vulnerability",
            "summary": "Windows Deployment Services Denial of Service Vulnerability",
            "score": 6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00661,
            "epssPercentile": 0.49345,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21349",
            "title": "Windows Remote Desktop Configuration Service Tampering Vulnerability",
            "summary": "Windows Remote Desktop Configuration Service Tampering Vulnerability",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0115,
            "epssPercentile": 0.64803,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21350",
            "title": "Windows Kerberos Denial of Service Vulnerability",
            "summary": "Windows Kerberos Denial of Service Vulnerability",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02145,
            "epssPercentile": 0.80877,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21351",
            "title": "Windows Active Directory Domain Services API Denial of Service Vulnerability",
            "summary": "Windows Active Directory Domain Services API Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02495,
            "epssPercentile": 0.83606,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21352",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01043,
            "epssPercentile": 0.61852,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21358",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00766,
            "epssPercentile": 0.53143,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21359",
            "title": "Windows Kernel Security Feature Bypass Vulnerability",
            "summary": "Windows Kernel Security Feature Bypass Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00566,
            "epssPercentile": 0.44897,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21367",
            "title": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "summary": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00648,
            "epssPercentile": 0.48786,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21368",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02169,
            "epssPercentile": 0.81087,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21369",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02169,
            "epssPercentile": 0.81088,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21371",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02453,
            "epssPercentile": 0.83331,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21373",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00807,
            "epssPercentile": 0.5446,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21375",
            "title": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "summary": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00648,
            "epssPercentile": 0.48786,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21376",
            "title": "Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability",
            "summary": "Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.09389,
            "epssPercentile": 0.95064,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21377",
            "title": "NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "NTLM Hash Disclosure Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.24457,
            "epssPercentile": 0.97722,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21391",
            "title": "Microsoft Windows Storage Link Following Vulnerability",
            "summary": "Microsoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow an attacker to delete data including data that results in the service being unavailable.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-02-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02303,
            "epssPercentile": 0.82202,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-03-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21406",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21407",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21414",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00612,
            "epssPercentile": 0.47099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21418",
            "title": "Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-02-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01568,
            "epssPercentile": 0.73701,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-03-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21419",
            "title": "Windows Setup Files Cleanup Elevation of Privilege Vulnerability",
            "summary": "Windows Setup Files Cleanup Elevation of Privilege Vulnerability",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0073,
            "epssPercentile": 0.51932,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21420",
            "title": "Windows Disk Cleanup Tool Elevation of Privilege Vulnerability",
            "summary": "Windows Disk Cleanup Tool Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03699,
            "epssPercentile": 0.88996,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-esu-kb5051989",
      "slug": "microsoft-2025-02-esu-kb5051989",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5051989",
      "title": "Deploy Microsoft ESU security update KB5051989",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5051989",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Windows 11 Version 22H2 for ARM64-based Systems, Windows 11 Version 22H2 for x64-based Systems",
      "platform": "ESU",
      "release_version": "10.0.22621.4890",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21407",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows 11 Version 22H2 for ARM64-based Systems, Windows 11 Version 22H2 for x64-based Systems exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 31 linked CVEs for Windows 11 Version 22H2 for ARM64-based Systems, Windows 11 Version 22H2 for x64-based Systems. Microsoft reports exploitation for CVE-2025-21391, CVE-2025-21418.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 31,
        "ids": [
          "CVE-2025-21181",
          "CVE-2025-21184",
          "CVE-2025-21190",
          "CVE-2025-21200",
          "CVE-2025-21201",
          "CVE-2025-21212",
          "CVE-2025-21216",
          "CVE-2025-21254",
          "CVE-2025-21337",
          "CVE-2025-21347",
          "CVE-2025-21349",
          "CVE-2025-21350",
          "CVE-2025-21351",
          "CVE-2025-21352",
          "CVE-2025-21358",
          "CVE-2025-21359",
          "CVE-2025-21367",
          "CVE-2025-21368",
          "CVE-2025-21369",
          "CVE-2025-21371",
          "CVE-2025-21373",
          "CVE-2025-21375",
          "CVE-2025-21376",
          "CVE-2025-21377",
          "CVE-2025-21391",
          "CVE-2025-21406",
          "CVE-2025-21407",
          "CVE-2025-21414",
          "CVE-2025-21418",
          "CVE-2025-21419",
          "CVE-2025-21420"
        ],
        "details": [
          {
            "id": "CVE-2025-21181",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03511,
            "epssPercentile": 0.88429,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21184",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0061,
            "epssPercentile": 0.46994,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21190",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21200",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21201",
            "title": "Windows Telephony Server Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Server Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21212",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0104,
            "epssPercentile": 0.61739,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21216",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0104,
            "epssPercentile": 0.61739,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21254",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01043,
            "epssPercentile": 0.61852,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21337",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Windows NTFS Elevation of Privilege Vulnerability",
            "score": 3.3,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00613,
            "epssPercentile": 0.47117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21347",
            "title": "Windows Deployment Services Denial of Service Vulnerability",
            "summary": "Windows Deployment Services Denial of Service Vulnerability",
            "score": 6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00661,
            "epssPercentile": 0.49345,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21349",
            "title": "Windows Remote Desktop Configuration Service Tampering Vulnerability",
            "summary": "Windows Remote Desktop Configuration Service Tampering Vulnerability",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0115,
            "epssPercentile": 0.64803,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21350",
            "title": "Windows Kerberos Denial of Service Vulnerability",
            "summary": "Windows Kerberos Denial of Service Vulnerability",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02145,
            "epssPercentile": 0.80877,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21351",
            "title": "Windows Active Directory Domain Services API Denial of Service Vulnerability",
            "summary": "Windows Active Directory Domain Services API Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02495,
            "epssPercentile": 0.83606,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21352",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01043,
            "epssPercentile": 0.61852,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21358",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00766,
            "epssPercentile": 0.53143,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21359",
            "title": "Windows Kernel Security Feature Bypass Vulnerability",
            "summary": "Windows Kernel Security Feature Bypass Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00566,
            "epssPercentile": 0.44897,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21367",
            "title": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "summary": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00648,
            "epssPercentile": 0.48786,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21368",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02169,
            "epssPercentile": 0.81087,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21369",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02169,
            "epssPercentile": 0.81088,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21371",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02453,
            "epssPercentile": 0.83331,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21373",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00807,
            "epssPercentile": 0.5446,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21375",
            "title": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "summary": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00648,
            "epssPercentile": 0.48786,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21376",
            "title": "Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability",
            "summary": "Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.09389,
            "epssPercentile": 0.95064,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21377",
            "title": "NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "NTLM Hash Disclosure Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.24457,
            "epssPercentile": 0.97722,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21391",
            "title": "Microsoft Windows Storage Link Following Vulnerability",
            "summary": "Microsoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow an attacker to delete data including data that results in the service being unavailable.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-02-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02303,
            "epssPercentile": 0.82202,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-03-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21406",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21407",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21414",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00612,
            "epssPercentile": 0.47099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21418",
            "title": "Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-02-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01568,
            "epssPercentile": 0.73701,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-03-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21419",
            "title": "Windows Setup Files Cleanup Elevation of Privilege Vulnerability",
            "summary": "Windows Setup Files Cleanup Elevation of Privilege Vulnerability",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0073,
            "epssPercentile": 0.51932,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21420",
            "title": "Windows Disk Cleanup Tool Elevation of Privilege Vulnerability",
            "summary": "Windows Disk Cleanup Tool Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03699,
            "epssPercentile": 0.88996,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-esu-kb5052016",
      "slug": "microsoft-2025-02-esu-kb5052016",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5052016",
      "title": "Deploy Microsoft ESU security update KB5052016",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5052016",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)",
      "platform": "ESU",
      "release_version": "6.1.7601.27566",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21410",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 21 linked CVEs for Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation). Microsoft reports exploitation for CVE-2025-21418.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 21,
        "ids": [
          "CVE-2025-21181",
          "CVE-2025-21190",
          "CVE-2025-21200",
          "CVE-2025-21201",
          "CVE-2025-21208",
          "CVE-2025-21337",
          "CVE-2025-21350",
          "CVE-2025-21352",
          "CVE-2025-21359",
          "CVE-2025-21368",
          "CVE-2025-21369",
          "CVE-2025-21371",
          "CVE-2025-21373",
          "CVE-2025-21375",
          "CVE-2025-21376",
          "CVE-2025-21377",
          "CVE-2025-21406",
          "CVE-2025-21407",
          "CVE-2025-21410",
          "CVE-2025-21418",
          "CVE-2025-21419"
        ],
        "details": [
          {
            "id": "CVE-2025-21181",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03511,
            "epssPercentile": 0.88429,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21190",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21200",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21201",
            "title": "Windows Telephony Server Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Server Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21208",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77412,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21337",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Windows NTFS Elevation of Privilege Vulnerability",
            "score": 3.3,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00613,
            "epssPercentile": 0.47117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21350",
            "title": "Windows Kerberos Denial of Service Vulnerability",
            "summary": "Windows Kerberos Denial of Service Vulnerability",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02145,
            "epssPercentile": 0.80877,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21352",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01043,
            "epssPercentile": 0.61852,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21359",
            "title": "Windows Kernel Security Feature Bypass Vulnerability",
            "summary": "Windows Kernel Security Feature Bypass Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00566,
            "epssPercentile": 0.44897,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21368",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02169,
            "epssPercentile": 0.81087,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21369",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02169,
            "epssPercentile": 0.81088,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21371",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02453,
            "epssPercentile": 0.83331,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21373",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00807,
            "epssPercentile": 0.5446,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21375",
            "title": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "summary": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00648,
            "epssPercentile": 0.48786,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21376",
            "title": "Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability",
            "summary": "Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.09389,
            "epssPercentile": 0.95064,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21377",
            "title": "NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "NTLM Hash Disclosure Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.24457,
            "epssPercentile": 0.97722,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21406",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21407",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21410",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21418",
            "title": "Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-02-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01568,
            "epssPercentile": 0.73701,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-03-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21419",
            "title": "Windows Setup Files Cleanup Elevation of Privilege Vulnerability",
            "summary": "Windows Setup Files Cleanup Elevation of Privilege Vulnerability",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0073,
            "epssPercentile": 0.51932,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-esu-kb5052020",
      "slug": "microsoft-2025-02-esu-kb5052020",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5052020",
      "title": "Deploy Microsoft ESU security update KB5052020",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5052020",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Windows Server 2012, Windows Server 2012 (Server Core installation)",
      "platform": "ESU",
      "release_version": "6.2.9200.25317",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21410",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows Server 2012, Windows Server 2012 (Server Core installation) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 23 linked CVEs for Windows Server 2012, Windows Server 2012 (Server Core installation). Microsoft reports exploitation for CVE-2025-21418.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 23,
        "ids": [
          "CVE-2025-21181",
          "CVE-2025-21190",
          "CVE-2025-21200",
          "CVE-2025-21201",
          "CVE-2025-21208",
          "CVE-2025-21337",
          "CVE-2025-21347",
          "CVE-2025-21350",
          "CVE-2025-21352",
          "CVE-2025-21359",
          "CVE-2025-21368",
          "CVE-2025-21369",
          "CVE-2025-21371",
          "CVE-2025-21373",
          "CVE-2025-21375",
          "CVE-2025-21376",
          "CVE-2025-21377",
          "CVE-2025-21406",
          "CVE-2025-21407",
          "CVE-2025-21410",
          "CVE-2025-21418",
          "CVE-2025-21419",
          "CVE-2025-21420"
        ],
        "details": [
          {
            "id": "CVE-2025-21181",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03511,
            "epssPercentile": 0.88429,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21190",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21200",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21201",
            "title": "Windows Telephony Server Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Server Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21208",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77412,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21337",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Windows NTFS Elevation of Privilege Vulnerability",
            "score": 3.3,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00613,
            "epssPercentile": 0.47117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21347",
            "title": "Windows Deployment Services Denial of Service Vulnerability",
            "summary": "Windows Deployment Services Denial of Service Vulnerability",
            "score": 6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00661,
            "epssPercentile": 0.49345,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21350",
            "title": "Windows Kerberos Denial of Service Vulnerability",
            "summary": "Windows Kerberos Denial of Service Vulnerability",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02145,
            "epssPercentile": 0.80877,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21352",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01043,
            "epssPercentile": 0.61852,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21359",
            "title": "Windows Kernel Security Feature Bypass Vulnerability",
            "summary": "Windows Kernel Security Feature Bypass Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00566,
            "epssPercentile": 0.44897,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21368",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02169,
            "epssPercentile": 0.81087,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21369",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02169,
            "epssPercentile": 0.81088,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21371",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02453,
            "epssPercentile": 0.83331,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21373",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00807,
            "epssPercentile": 0.5446,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21375",
            "title": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "summary": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00648,
            "epssPercentile": 0.48786,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21376",
            "title": "Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability",
            "summary": "Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.09389,
            "epssPercentile": 0.95064,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21377",
            "title": "NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "NTLM Hash Disclosure Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.24457,
            "epssPercentile": 0.97722,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21406",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21407",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21410",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21418",
            "title": "Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-02-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01568,
            "epssPercentile": 0.73701,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-03-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21419",
            "title": "Windows Setup Files Cleanup Elevation of Privilege Vulnerability",
            "summary": "Windows Setup Files Cleanup Elevation of Privilege Vulnerability",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0073,
            "epssPercentile": 0.51932,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21420",
            "title": "Windows Disk Cleanup Tool Elevation of Privilege Vulnerability",
            "summary": "Windows Disk Cleanup Tool Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03699,
            "epssPercentile": 0.88996,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-esu-kb5052032",
      "slug": "microsoft-2025-02-esu-kb5052032",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5052032",
      "title": "Deploy Microsoft ESU security update KB5052032",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5052032",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)",
      "platform": "ESU",
      "release_version": "6.1.7601.27566",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21410",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 20 linked CVEs for Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation). Microsoft reports exploitation for CVE-2025-21418.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 20,
        "ids": [
          "CVE-2025-21181",
          "CVE-2025-21190",
          "CVE-2025-21200",
          "CVE-2025-21201",
          "CVE-2025-21208",
          "CVE-2025-21337",
          "CVE-2025-21350",
          "CVE-2025-21352",
          "CVE-2025-21359",
          "CVE-2025-21368",
          "CVE-2025-21369",
          "CVE-2025-21371",
          "CVE-2025-21373",
          "CVE-2025-21375",
          "CVE-2025-21376",
          "CVE-2025-21406",
          "CVE-2025-21407",
          "CVE-2025-21410",
          "CVE-2025-21418",
          "CVE-2025-21419"
        ],
        "details": [
          {
            "id": "CVE-2025-21181",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03511,
            "epssPercentile": 0.88429,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21190",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21200",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21201",
            "title": "Windows Telephony Server Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Server Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21208",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77412,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21337",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Windows NTFS Elevation of Privilege Vulnerability",
            "score": 3.3,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00613,
            "epssPercentile": 0.47117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21350",
            "title": "Windows Kerberos Denial of Service Vulnerability",
            "summary": "Windows Kerberos Denial of Service Vulnerability",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02145,
            "epssPercentile": 0.80877,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21352",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01043,
            "epssPercentile": 0.61852,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21359",
            "title": "Windows Kernel Security Feature Bypass Vulnerability",
            "summary": "Windows Kernel Security Feature Bypass Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00566,
            "epssPercentile": 0.44897,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21368",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02169,
            "epssPercentile": 0.81087,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21369",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02169,
            "epssPercentile": 0.81088,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21371",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02453,
            "epssPercentile": 0.83331,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21373",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00807,
            "epssPercentile": 0.5446,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21375",
            "title": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "summary": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00648,
            "epssPercentile": 0.48786,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21376",
            "title": "Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability",
            "summary": "Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.09389,
            "epssPercentile": 0.95064,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21406",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21407",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21410",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21418",
            "title": "Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-02-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01568,
            "epssPercentile": 0.73701,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-03-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21419",
            "title": "Windows Setup Files Cleanup Elevation of Privilege Vulnerability",
            "summary": "Windows Setup Files Cleanup Elevation of Privilege Vulnerability",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0073,
            "epssPercentile": 0.51932,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-esu-kb5052038",
      "slug": "microsoft-2025-02-esu-kb5052038",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5052038",
      "title": "Deploy Microsoft ESU security update KB5052038",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5052038",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more",
      "platform": "ESU",
      "release_version": "6.0.6003.23117",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21410",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 20 linked CVEs for Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more. Microsoft reports exploitation for CVE-2025-21418.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 20,
        "ids": [
          "CVE-2025-21181",
          "CVE-2025-21190",
          "CVE-2025-21200",
          "CVE-2025-21201",
          "CVE-2025-21208",
          "CVE-2025-21337",
          "CVE-2025-21350",
          "CVE-2025-21352",
          "CVE-2025-21359",
          "CVE-2025-21368",
          "CVE-2025-21369",
          "CVE-2025-21371",
          "CVE-2025-21373",
          "CVE-2025-21375",
          "CVE-2025-21376",
          "CVE-2025-21377",
          "CVE-2025-21406",
          "CVE-2025-21407",
          "CVE-2025-21410",
          "CVE-2025-21418"
        ],
        "details": [
          {
            "id": "CVE-2025-21181",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03511,
            "epssPercentile": 0.88429,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21190",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21200",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21201",
            "title": "Windows Telephony Server Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Server Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21208",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77412,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21337",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Windows NTFS Elevation of Privilege Vulnerability",
            "score": 3.3,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00613,
            "epssPercentile": 0.47117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21350",
            "title": "Windows Kerberos Denial of Service Vulnerability",
            "summary": "Windows Kerberos Denial of Service Vulnerability",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02145,
            "epssPercentile": 0.80877,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21352",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01043,
            "epssPercentile": 0.61852,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21359",
            "title": "Windows Kernel Security Feature Bypass Vulnerability",
            "summary": "Windows Kernel Security Feature Bypass Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00566,
            "epssPercentile": 0.44897,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21368",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02169,
            "epssPercentile": 0.81087,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21369",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02169,
            "epssPercentile": 0.81088,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21371",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02453,
            "epssPercentile": 0.83331,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21373",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00807,
            "epssPercentile": 0.5446,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21375",
            "title": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "summary": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00648,
            "epssPercentile": 0.48786,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21376",
            "title": "Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability",
            "summary": "Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.09389,
            "epssPercentile": 0.95064,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21377",
            "title": "NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "NTLM Hash Disclosure Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.24457,
            "epssPercentile": 0.97722,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21406",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21407",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21410",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21418",
            "title": "Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-02-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01568,
            "epssPercentile": 0.73701,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-03-04 as the remediation due date.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-esu-kb5052042",
      "slug": "microsoft-2025-02-esu-kb5052042",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5052042",
      "title": "Deploy Microsoft ESU security update KB5052042",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5052042",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)",
      "platform": "ESU",
      "release_version": "6.3.9600.22417",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21410",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 23 linked CVEs for Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation). Microsoft reports exploitation for CVE-2025-21418.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 23,
        "ids": [
          "CVE-2025-21181",
          "CVE-2025-21190",
          "CVE-2025-21200",
          "CVE-2025-21201",
          "CVE-2025-21208",
          "CVE-2025-21337",
          "CVE-2025-21347",
          "CVE-2025-21350",
          "CVE-2025-21352",
          "CVE-2025-21359",
          "CVE-2025-21368",
          "CVE-2025-21369",
          "CVE-2025-21371",
          "CVE-2025-21373",
          "CVE-2025-21375",
          "CVE-2025-21376",
          "CVE-2025-21377",
          "CVE-2025-21406",
          "CVE-2025-21407",
          "CVE-2025-21410",
          "CVE-2025-21418",
          "CVE-2025-21419",
          "CVE-2025-21420"
        ],
        "details": [
          {
            "id": "CVE-2025-21181",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03511,
            "epssPercentile": 0.88429,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21190",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21200",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21201",
            "title": "Windows Telephony Server Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Server Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21208",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77412,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21337",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Windows NTFS Elevation of Privilege Vulnerability",
            "score": 3.3,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00613,
            "epssPercentile": 0.47117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21347",
            "title": "Windows Deployment Services Denial of Service Vulnerability",
            "summary": "Windows Deployment Services Denial of Service Vulnerability",
            "score": 6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00661,
            "epssPercentile": 0.49345,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21350",
            "title": "Windows Kerberos Denial of Service Vulnerability",
            "summary": "Windows Kerberos Denial of Service Vulnerability",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02145,
            "epssPercentile": 0.80877,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21352",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01043,
            "epssPercentile": 0.61852,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21359",
            "title": "Windows Kernel Security Feature Bypass Vulnerability",
            "summary": "Windows Kernel Security Feature Bypass Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00566,
            "epssPercentile": 0.44897,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21368",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02169,
            "epssPercentile": 0.81087,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21369",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02169,
            "epssPercentile": 0.81088,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21371",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02453,
            "epssPercentile": 0.83331,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21373",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00807,
            "epssPercentile": 0.5446,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21375",
            "title": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "summary": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00648,
            "epssPercentile": 0.48786,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21376",
            "title": "Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability",
            "summary": "Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.09389,
            "epssPercentile": 0.95064,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21377",
            "title": "NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "NTLM Hash Disclosure Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.24457,
            "epssPercentile": 0.97722,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21406",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21407",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21410",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21418",
            "title": "Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-02-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01568,
            "epssPercentile": 0.73701,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-03-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21419",
            "title": "Windows Setup Files Cleanup Elevation of Privilege Vulnerability",
            "summary": "Windows Setup Files Cleanup Elevation of Privilege Vulnerability",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0073,
            "epssPercentile": 0.51932,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21420",
            "title": "Windows Disk Cleanup Tool Elevation of Privilege Vulnerability",
            "summary": "Windows Disk Cleanup Tool Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03699,
            "epssPercentile": 0.88996,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-esu-kb5052072",
      "slug": "microsoft-2025-02-esu-kb5052072",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5052072",
      "title": "Deploy Microsoft ESU security update KB5052072",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5052072",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more",
      "platform": "ESU",
      "release_version": "6.0.6003.23117",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21410",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 19 linked CVEs for Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more. Microsoft reports exploitation for CVE-2025-21418.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 19,
        "ids": [
          "CVE-2025-21181",
          "CVE-2025-21190",
          "CVE-2025-21200",
          "CVE-2025-21201",
          "CVE-2025-21208",
          "CVE-2025-21337",
          "CVE-2025-21350",
          "CVE-2025-21352",
          "CVE-2025-21359",
          "CVE-2025-21368",
          "CVE-2025-21369",
          "CVE-2025-21371",
          "CVE-2025-21373",
          "CVE-2025-21375",
          "CVE-2025-21376",
          "CVE-2025-21406",
          "CVE-2025-21407",
          "CVE-2025-21410",
          "CVE-2025-21418"
        ],
        "details": [
          {
            "id": "CVE-2025-21181",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03511,
            "epssPercentile": 0.88429,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21190",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21200",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21201",
            "title": "Windows Telephony Server Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Server Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21208",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77412,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21337",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Windows NTFS Elevation of Privilege Vulnerability",
            "score": 3.3,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00613,
            "epssPercentile": 0.47117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21350",
            "title": "Windows Kerberos Denial of Service Vulnerability",
            "summary": "Windows Kerberos Denial of Service Vulnerability",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02145,
            "epssPercentile": 0.80877,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21352",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01043,
            "epssPercentile": 0.61852,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21359",
            "title": "Windows Kernel Security Feature Bypass Vulnerability",
            "summary": "Windows Kernel Security Feature Bypass Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00566,
            "epssPercentile": 0.44897,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21368",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02169,
            "epssPercentile": 0.81087,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21369",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02169,
            "epssPercentile": 0.81088,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21371",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02453,
            "epssPercentile": 0.83331,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21373",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00807,
            "epssPercentile": 0.5446,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21375",
            "title": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "summary": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00648,
            "epssPercentile": 0.48786,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21376",
            "title": "Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability",
            "summary": "Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.09389,
            "epssPercentile": 0.95064,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21406",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21407",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21410",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21418",
            "title": "Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-02-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01568,
            "epssPercentile": 0.73701,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-03-04 as the remediation due date.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-microsoft-office-kb5002179",
      "slug": "microsoft-2025-02-microsoft-office-kb5002179",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002179",
      "title": "Deploy Microsoft Microsoft Office security update KB5002179",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002179",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Microsoft Excel 2016 (32-bit edition), Microsoft Excel 2016 (64-bit edition)",
      "platform": "Microsoft Office",
      "release_version": "16.0.5487.1000",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21390",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Excel 2016 (32-bit edition), Microsoft Excel 2016 (64-bit edition) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Microsoft Excel 2016 (32-bit edition), Microsoft Excel 2016 (64-bit edition).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 2,
        "ids": [
          "CVE-2025-21383",
          "CVE-2025-21390"
        ],
        "details": [
          {
            "id": "CVE-2025-21383",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Microsoft Excel Information Disclosure Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01016,
            "epssPercentile": 0.61024,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21390",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Microsoft Excel Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00843,
            "epssPercentile": 0.55591,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-microsoft-office-kb5002678",
      "slug": "microsoft-2025-02-microsoft-office-kb5002678",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002678",
      "title": "Deploy Microsoft Microsoft Office security update KB5002678",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002678",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Microsoft SharePoint Server 2019",
      "platform": "Microsoft Office",
      "release_version": "16.0.10416.20050",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21400",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft SharePoint Server 2019 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft SharePoint Server 2019.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21400"
        ],
        "details": [
          {
            "id": "CVE-2025-21400",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.34488,
            "epssPercentile": 0.98306,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-microsoft-office-kb5002679",
      "slug": "microsoft-2025-02-microsoft-office-kb5002679",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002679",
      "title": "Deploy Microsoft Microsoft Office security update KB5002679",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002679",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Office Online Server",
      "platform": "Microsoft Office",
      "release_version": "16.0.10416.20058",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21394",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Office Online Server exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 5 linked CVEs for Office Online Server.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 5,
        "ids": [
          "CVE-2025-21381",
          "CVE-2025-21386",
          "CVE-2025-21387",
          "CVE-2025-21390",
          "CVE-2025-21394"
        ],
        "details": [
          {
            "id": "CVE-2025-21381",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Microsoft Excel Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01145,
            "epssPercentile": 0.64626,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21386",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Microsoft Excel Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00843,
            "epssPercentile": 0.55592,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21387",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Microsoft Excel Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00942,
            "epssPercentile": 0.58696,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21390",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Microsoft Excel Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00843,
            "epssPercentile": 0.55591,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21394",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Microsoft Excel Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00843,
            "epssPercentile": 0.55592,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-microsoft-office-kb5002681",
      "slug": "microsoft-2025-02-microsoft-office-kb5002681",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002681",
      "title": "Deploy Microsoft Microsoft Office security update KB5002681",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002681",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Microsoft SharePoint Server Subscription Edition",
      "platform": "Microsoft Office",
      "release_version": "16.0.17928.20396",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21400",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft SharePoint Server Subscription Edition exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft SharePoint Server Subscription Edition.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21400"
        ],
        "details": [
          {
            "id": "CVE-2025-21400",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.34488,
            "epssPercentile": 0.98306,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-microsoft-office-kb5002684",
      "slug": "microsoft-2025-02-microsoft-office-kb5002684",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002684",
      "title": "Deploy Microsoft Microsoft Office security update KB5002684",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002684",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Microsoft Excel 2016 (32-bit edition), Microsoft Excel 2016 (64-bit edition)",
      "platform": "Microsoft Office",
      "release_version": "16.0.5487.1000",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21387",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Excel 2016 (32-bit edition), Microsoft Excel 2016 (64-bit edition) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Excel 2016 (32-bit edition), Microsoft Excel 2016 (64-bit edition).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21387"
        ],
        "details": [
          {
            "id": "CVE-2025-21387",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Microsoft Excel Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00942,
            "epssPercentile": 0.58696,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-microsoft-office-kb5002685",
      "slug": "microsoft-2025-02-microsoft-office-kb5002685",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002685",
      "title": "Deploy Microsoft Microsoft Office security update KB5002685",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002685",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "platform": "Microsoft Office",
      "release_version": "16.0.5487.1000",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21400",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft SharePoint Enterprise Server 2016 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft SharePoint Enterprise Server 2016.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21400"
        ],
        "details": [
          {
            "id": "CVE-2025-21400",
            "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "summary": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
            "score": 8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.34488,
            "epssPercentile": 0.98306,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-microsoft-office-kb5002686",
      "slug": "microsoft-2025-02-microsoft-office-kb5002686",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002686",
      "title": "Deploy Microsoft Microsoft Office security update KB5002686",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002686",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition)",
      "platform": "Microsoft Office",
      "release_version": "16.0.5487.1000",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21392",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21392"
        ],
        "details": [
          {
            "id": "CVE-2025-21392",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Microsoft Office Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00843,
            "epssPercentile": 0.55592,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-microsoft-office-kb5002687",
      "slug": "microsoft-2025-02-microsoft-office-kb5002687",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002687",
      "title": "Deploy Microsoft Microsoft Office security update KB5002687",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002687",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Microsoft Excel 2016 (32-bit edition), Microsoft Excel 2016 (64-bit edition)",
      "platform": "Microsoft Office",
      "release_version": "16.0.5487.1000",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21394",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Excel 2016 (32-bit edition), Microsoft Excel 2016 (64-bit edition) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 5 linked CVEs for Microsoft Excel 2016 (32-bit edition), Microsoft Excel 2016 (64-bit edition).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 5,
        "ids": [
          "CVE-2025-21381",
          "CVE-2025-21386",
          "CVE-2025-21387",
          "CVE-2025-21390",
          "CVE-2025-21394"
        ],
        "details": [
          {
            "id": "CVE-2025-21381",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Microsoft Excel Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01145,
            "epssPercentile": 0.64626,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21386",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Microsoft Excel Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00843,
            "epssPercentile": 0.55592,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21387",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Microsoft Excel Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00942,
            "epssPercentile": 0.58696,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21390",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Microsoft Excel Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00843,
            "epssPercentile": 0.55591,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21394",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Microsoft Excel Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00843,
            "epssPercentile": 0.55592,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-microsoft-office-msrc-2025-02-microsoft-office-click-to-run-microsoft-365-apps-for-enterprise-for-32-bit-systems-microsoft-365-apps-for-enterprise-for-64-bit-systems-micr",
      "slug": "microsoft-2025-02-microsoft-office-msrc-2025-02-microsoft-office-click-to-run-microsoft-365-apps-for-enterprise-for-32-bit-systems-microsoft-365-apps-for-enterprise-for-64-bit-systems-micr",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-02-microsoft-office-click-to-run",
      "title": "Deploy Microsoft Microsoft Office update for Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office 2019 for 32-bit editions, plus 5 more",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://msrc.microsoft.com/update-guide/releaseNote/2025-Feb",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office 2019 for 32-bit editions, plus 5 more",
      "platform": "Microsoft Office",
      "release_version": "https://aka.ms/OfficeSecurityReleases",
      "action_type": "deploy-patch",
      "restart_required": "no",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21397",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "The reviewed source does not require a restart.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office 2019 for 32-bit editions, plus 5 more exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 8 linked CVEs for Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office 2019 for 32-bit editions, plus 5 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 8,
        "ids": [
          "CVE-2025-21381",
          "CVE-2025-21383",
          "CVE-2025-21386",
          "CVE-2025-21387",
          "CVE-2025-21390",
          "CVE-2025-21392",
          "CVE-2025-21394",
          "CVE-2025-21397"
        ],
        "details": [
          {
            "id": "CVE-2025-21381",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Microsoft Excel Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01145,
            "epssPercentile": 0.64626,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21383",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Microsoft Excel Information Disclosure Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01016,
            "epssPercentile": 0.61024,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21386",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Microsoft Excel Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00843,
            "epssPercentile": 0.55592,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21387",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Microsoft Excel Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00942,
            "epssPercentile": 0.58696,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21390",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Microsoft Excel Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00843,
            "epssPercentile": 0.55591,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21392",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Microsoft Office Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00843,
            "epssPercentile": 0.55592,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21394",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Microsoft Excel Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00843,
            "epssPercentile": 0.55592,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21397",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Microsoft Office Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00782,
            "epssPercentile": 0.5366,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-microsoft-office-msrc-2025-02-microsoft-office-release-notes-microsoft-office-ltsc-for-mac-2021",
      "slug": "microsoft-2025-02-microsoft-office-msrc-2025-02-microsoft-office-release-notes-microsoft-office-ltsc-for-mac-2021",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-02-microsoft-office-release-notes",
      "title": "Deploy Microsoft Microsoft Office update for Microsoft Office LTSC for Mac 2021",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://go.microsoft.com/fwlink/p/?linkid=831049",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Microsoft Office LTSC for Mac 2021",
      "platform": "Microsoft Office",
      "release_version": "16.94.25020927",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21394",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Office LTSC for Mac 2021 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 7 linked CVEs for Microsoft Office LTSC for Mac 2021.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 7,
        "ids": [
          "CVE-2025-21381",
          "CVE-2025-21383",
          "CVE-2025-21386",
          "CVE-2025-21387",
          "CVE-2025-21390",
          "CVE-2025-21392",
          "CVE-2025-21394"
        ],
        "details": [
          {
            "id": "CVE-2025-21381",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Microsoft Excel Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01145,
            "epssPercentile": 0.64626,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21383",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Microsoft Excel Information Disclosure Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01016,
            "epssPercentile": 0.61024,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21386",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Microsoft Excel Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00843,
            "epssPercentile": 0.55592,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21387",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Microsoft Excel Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00942,
            "epssPercentile": 0.58696,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21390",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Microsoft Excel Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00843,
            "epssPercentile": 0.55591,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21392",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Microsoft Office Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00843,
            "epssPercentile": 0.55592,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21394",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Microsoft Excel Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00843,
            "epssPercentile": 0.55592,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-microsoft-office-msrc-2025-02-microsoft-office-release-notes-microsoft-office-ltsc-for-mac-2024",
      "slug": "microsoft-2025-02-microsoft-office-msrc-2025-02-microsoft-office-release-notes-microsoft-office-ltsc-for-mac-2024",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-02-microsoft-office-release-notes",
      "title": "Deploy Microsoft Microsoft Office update for Microsoft Office LTSC for Mac 2024",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://go.microsoft.com/fwlink/p/?linkid=831049",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Microsoft Office LTSC for Mac 2024",
      "platform": "Microsoft Office",
      "release_version": "16.94.25020927",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21394",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Office LTSC for Mac 2024 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 7 linked CVEs for Microsoft Office LTSC for Mac 2024.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 7,
        "ids": [
          "CVE-2025-21381",
          "CVE-2025-21383",
          "CVE-2025-21386",
          "CVE-2025-21387",
          "CVE-2025-21390",
          "CVE-2025-21392",
          "CVE-2025-21394"
        ],
        "details": [
          {
            "id": "CVE-2025-21381",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Microsoft Excel Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01145,
            "epssPercentile": 0.64626,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21383",
            "title": "Microsoft Excel Information Disclosure Vulnerability",
            "summary": "Microsoft Excel Information Disclosure Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01016,
            "epssPercentile": 0.61024,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21386",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Microsoft Excel Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00843,
            "epssPercentile": 0.55592,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21387",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Microsoft Excel Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00942,
            "epssPercentile": 0.58696,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21390",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Microsoft Excel Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00843,
            "epssPercentile": 0.55591,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21392",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Microsoft Office Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00843,
            "epssPercentile": 0.55592,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21394",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Microsoft Excel Remote Code Execution Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00843,
            "epssPercentile": 0.55592,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-microsoft-office-msrc-2025-02-microsoft-office-release-notes-microsoft-autoupdate-for-mac",
      "slug": "microsoft-2025-02-microsoft-office-msrc-2025-02-microsoft-office-release-notes-microsoft-autoupdate-for-mac",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-02-microsoft-office-release-notes",
      "title": "Deploy Microsoft Microsoft Office update for Microsoft AutoUpdate for Mac",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://officecdnmac.microsoft.com/pr/C1297A47-86C4-4C1F-97FA-950631F94777/MacAutoupdate/Microsoft_AutoUpdate_4.78.25022527_Updater.pkg",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Microsoft AutoUpdate for Mac",
      "platform": "Microsoft Office",
      "release_version": "4.78.25022527",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-24036",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft AutoUpdate for Mac exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft AutoUpdate for Mac.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-24036"
        ],
        "details": [
          {
            "id": "CVE-2025-24036",
            "title": "Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability",
            "summary": "Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00368,
            "epssPercentile": 0.29892,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-windows-kb5051974",
      "slug": "microsoft-2025-02-windows-kb5051974",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5051974",
      "title": "Deploy Microsoft Windows security update KB5051974",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5051974",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems",
      "platform": "Windows",
      "release_version": "10.0.19044.5487",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21407",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 31 linked CVEs for Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems. Microsoft reports exploitation for CVE-2025-21391, CVE-2025-21418.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 31,
        "ids": [
          "CVE-2025-21181",
          "CVE-2025-21184",
          "CVE-2025-21190",
          "CVE-2025-21200",
          "CVE-2025-21201",
          "CVE-2025-21212",
          "CVE-2025-21216",
          "CVE-2025-21254",
          "CVE-2025-21337",
          "CVE-2025-21347",
          "CVE-2025-21349",
          "CVE-2025-21350",
          "CVE-2025-21351",
          "CVE-2025-21352",
          "CVE-2025-21358",
          "CVE-2025-21359",
          "CVE-2025-21367",
          "CVE-2025-21368",
          "CVE-2025-21369",
          "CVE-2025-21371",
          "CVE-2025-21373",
          "CVE-2025-21375",
          "CVE-2025-21376",
          "CVE-2025-21377",
          "CVE-2025-21391",
          "CVE-2025-21406",
          "CVE-2025-21407",
          "CVE-2025-21414",
          "CVE-2025-21418",
          "CVE-2025-21419",
          "CVE-2025-21420"
        ],
        "details": [
          {
            "id": "CVE-2025-21181",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03511,
            "epssPercentile": 0.88429,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21184",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0061,
            "epssPercentile": 0.46994,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21190",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21200",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21201",
            "title": "Windows Telephony Server Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Server Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21212",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0104,
            "epssPercentile": 0.61739,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21216",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0104,
            "epssPercentile": 0.61739,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21254",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01043,
            "epssPercentile": 0.61852,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21337",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Windows NTFS Elevation of Privilege Vulnerability",
            "score": 3.3,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00613,
            "epssPercentile": 0.47117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21347",
            "title": "Windows Deployment Services Denial of Service Vulnerability",
            "summary": "Windows Deployment Services Denial of Service Vulnerability",
            "score": 6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00661,
            "epssPercentile": 0.49345,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21349",
            "title": "Windows Remote Desktop Configuration Service Tampering Vulnerability",
            "summary": "Windows Remote Desktop Configuration Service Tampering Vulnerability",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0115,
            "epssPercentile": 0.64803,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21350",
            "title": "Windows Kerberos Denial of Service Vulnerability",
            "summary": "Windows Kerberos Denial of Service Vulnerability",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02145,
            "epssPercentile": 0.80877,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21351",
            "title": "Windows Active Directory Domain Services API Denial of Service Vulnerability",
            "summary": "Windows Active Directory Domain Services API Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02495,
            "epssPercentile": 0.83606,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21352",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01043,
            "epssPercentile": 0.61852,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21358",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00766,
            "epssPercentile": 0.53143,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21359",
            "title": "Windows Kernel Security Feature Bypass Vulnerability",
            "summary": "Windows Kernel Security Feature Bypass Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00566,
            "epssPercentile": 0.44897,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21367",
            "title": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "summary": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00648,
            "epssPercentile": 0.48786,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21368",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02169,
            "epssPercentile": 0.81087,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21369",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02169,
            "epssPercentile": 0.81088,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21371",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02453,
            "epssPercentile": 0.83331,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21373",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00807,
            "epssPercentile": 0.5446,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21375",
            "title": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "summary": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00648,
            "epssPercentile": 0.48786,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21376",
            "title": "Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability",
            "summary": "Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.09389,
            "epssPercentile": 0.95064,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21377",
            "title": "NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "NTLM Hash Disclosure Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.24457,
            "epssPercentile": 0.97722,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21391",
            "title": "Microsoft Windows Storage Link Following Vulnerability",
            "summary": "Microsoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow an attacker to delete data including data that results in the service being unavailable.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-02-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02303,
            "epssPercentile": 0.82202,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-03-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21406",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21407",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21414",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00612,
            "epssPercentile": 0.47099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21418",
            "title": "Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-02-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01568,
            "epssPercentile": 0.73701,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-03-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21419",
            "title": "Windows Setup Files Cleanup Elevation of Privilege Vulnerability",
            "summary": "Windows Setup Files Cleanup Elevation of Privilege Vulnerability",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0073,
            "epssPercentile": 0.51932,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21420",
            "title": "Windows Disk Cleanup Tool Elevation of Privilege Vulnerability",
            "summary": "Windows Disk Cleanup Tool Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03699,
            "epssPercentile": 0.88996,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-windows-kb5051979",
      "slug": "microsoft-2025-02-windows-kb5051979",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5051979",
      "title": "Deploy Microsoft Windows security update KB5051979",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5051979",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Windows Server 2022, Windows Server 2022 (Server Core installation)",
      "platform": "Windows",
      "release_version": "10.0.20348.3207",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21410",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows Server 2022, Windows Server 2022 (Server Core installation) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 33 linked CVEs for Windows Server 2022, Windows Server 2022 (Server Core installation). Microsoft reports exploitation for CVE-2025-21391, CVE-2025-21418.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 33,
        "ids": [
          "CVE-2025-21181",
          "CVE-2025-21184",
          "CVE-2025-21190",
          "CVE-2025-21200",
          "CVE-2025-21201",
          "CVE-2025-21208",
          "CVE-2025-21212",
          "CVE-2025-21216",
          "CVE-2025-21254",
          "CVE-2025-21337",
          "CVE-2025-21347",
          "CVE-2025-21349",
          "CVE-2025-21350",
          "CVE-2025-21351",
          "CVE-2025-21352",
          "CVE-2025-21358",
          "CVE-2025-21359",
          "CVE-2025-21367",
          "CVE-2025-21368",
          "CVE-2025-21369",
          "CVE-2025-21371",
          "CVE-2025-21373",
          "CVE-2025-21375",
          "CVE-2025-21376",
          "CVE-2025-21377",
          "CVE-2025-21391",
          "CVE-2025-21406",
          "CVE-2025-21407",
          "CVE-2025-21410",
          "CVE-2025-21414",
          "CVE-2025-21418",
          "CVE-2025-21419",
          "CVE-2025-21420"
        ],
        "details": [
          {
            "id": "CVE-2025-21181",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03511,
            "epssPercentile": 0.88429,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21184",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0061,
            "epssPercentile": 0.46994,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21190",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21200",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21201",
            "title": "Windows Telephony Server Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Server Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21208",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77412,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21212",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0104,
            "epssPercentile": 0.61739,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21216",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0104,
            "epssPercentile": 0.61739,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21254",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01043,
            "epssPercentile": 0.61852,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21337",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Windows NTFS Elevation of Privilege Vulnerability",
            "score": 3.3,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00613,
            "epssPercentile": 0.47117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21347",
            "title": "Windows Deployment Services Denial of Service Vulnerability",
            "summary": "Windows Deployment Services Denial of Service Vulnerability",
            "score": 6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00661,
            "epssPercentile": 0.49345,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21349",
            "title": "Windows Remote Desktop Configuration Service Tampering Vulnerability",
            "summary": "Windows Remote Desktop Configuration Service Tampering Vulnerability",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0115,
            "epssPercentile": 0.64803,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21350",
            "title": "Windows Kerberos Denial of Service Vulnerability",
            "summary": "Windows Kerberos Denial of Service Vulnerability",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02145,
            "epssPercentile": 0.80877,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21351",
            "title": "Windows Active Directory Domain Services API Denial of Service Vulnerability",
            "summary": "Windows Active Directory Domain Services API Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02495,
            "epssPercentile": 0.83606,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21352",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01043,
            "epssPercentile": 0.61852,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21358",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00766,
            "epssPercentile": 0.53143,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21359",
            "title": "Windows Kernel Security Feature Bypass Vulnerability",
            "summary": "Windows Kernel Security Feature Bypass Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00566,
            "epssPercentile": 0.44897,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21367",
            "title": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "summary": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00648,
            "epssPercentile": 0.48786,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21368",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02169,
            "epssPercentile": 0.81087,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21369",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02169,
            "epssPercentile": 0.81088,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21371",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02453,
            "epssPercentile": 0.83331,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21373",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00807,
            "epssPercentile": 0.5446,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21375",
            "title": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "summary": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00648,
            "epssPercentile": 0.48786,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21376",
            "title": "Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability",
            "summary": "Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.09389,
            "epssPercentile": 0.95064,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21377",
            "title": "NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "NTLM Hash Disclosure Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.24457,
            "epssPercentile": 0.97722,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21391",
            "title": "Microsoft Windows Storage Link Following Vulnerability",
            "summary": "Microsoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow an attacker to delete data including data that results in the service being unavailable.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-02-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02303,
            "epssPercentile": 0.82202,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-03-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21406",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21407",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21410",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21414",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00612,
            "epssPercentile": 0.47099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21418",
            "title": "Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-02-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01568,
            "epssPercentile": 0.73701,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-03-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21419",
            "title": "Windows Setup Files Cleanup Elevation of Privilege Vulnerability",
            "summary": "Windows Setup Files Cleanup Elevation of Privilege Vulnerability",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0073,
            "epssPercentile": 0.51932,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21420",
            "title": "Windows Disk Cleanup Tool Elevation of Privilege Vulnerability",
            "summary": "Windows Disk Cleanup Tool Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03699,
            "epssPercentile": 0.88996,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-windows-kb5051980",
      "slug": "microsoft-2025-02-windows-kb5051980",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5051980",
      "title": "Deploy Microsoft Windows security update KB5051980",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5051980",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Windows Server 2022, 23H2 Edition (Server Core installation)",
      "platform": "Windows",
      "release_version": "10.0.25398.1425",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21410",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows Server 2022, 23H2 Edition (Server Core installation) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 33 linked CVEs for Windows Server 2022, 23H2 Edition (Server Core installation). Microsoft reports exploitation for CVE-2025-21391, CVE-2025-21418.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 33,
        "ids": [
          "CVE-2025-21181",
          "CVE-2025-21184",
          "CVE-2025-21190",
          "CVE-2025-21200",
          "CVE-2025-21201",
          "CVE-2025-21208",
          "CVE-2025-21212",
          "CVE-2025-21216",
          "CVE-2025-21254",
          "CVE-2025-21337",
          "CVE-2025-21347",
          "CVE-2025-21349",
          "CVE-2025-21350",
          "CVE-2025-21351",
          "CVE-2025-21352",
          "CVE-2025-21358",
          "CVE-2025-21359",
          "CVE-2025-21367",
          "CVE-2025-21368",
          "CVE-2025-21369",
          "CVE-2025-21371",
          "CVE-2025-21373",
          "CVE-2025-21375",
          "CVE-2025-21376",
          "CVE-2025-21377",
          "CVE-2025-21391",
          "CVE-2025-21406",
          "CVE-2025-21407",
          "CVE-2025-21410",
          "CVE-2025-21414",
          "CVE-2025-21418",
          "CVE-2025-21419",
          "CVE-2025-21420"
        ],
        "details": [
          {
            "id": "CVE-2025-21181",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03511,
            "epssPercentile": 0.88429,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21184",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0061,
            "epssPercentile": 0.46994,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21190",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21200",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21201",
            "title": "Windows Telephony Server Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Server Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21208",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77412,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21212",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0104,
            "epssPercentile": 0.61739,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21216",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0104,
            "epssPercentile": 0.61739,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21254",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01043,
            "epssPercentile": 0.61852,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21337",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Windows NTFS Elevation of Privilege Vulnerability",
            "score": 3.3,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00613,
            "epssPercentile": 0.47117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21347",
            "title": "Windows Deployment Services Denial of Service Vulnerability",
            "summary": "Windows Deployment Services Denial of Service Vulnerability",
            "score": 6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00661,
            "epssPercentile": 0.49345,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21349",
            "title": "Windows Remote Desktop Configuration Service Tampering Vulnerability",
            "summary": "Windows Remote Desktop Configuration Service Tampering Vulnerability",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0115,
            "epssPercentile": 0.64803,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21350",
            "title": "Windows Kerberos Denial of Service Vulnerability",
            "summary": "Windows Kerberos Denial of Service Vulnerability",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02145,
            "epssPercentile": 0.80877,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21351",
            "title": "Windows Active Directory Domain Services API Denial of Service Vulnerability",
            "summary": "Windows Active Directory Domain Services API Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02495,
            "epssPercentile": 0.83606,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21352",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01043,
            "epssPercentile": 0.61852,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21358",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00766,
            "epssPercentile": 0.53143,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21359",
            "title": "Windows Kernel Security Feature Bypass Vulnerability",
            "summary": "Windows Kernel Security Feature Bypass Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00566,
            "epssPercentile": 0.44897,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21367",
            "title": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "summary": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00648,
            "epssPercentile": 0.48786,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21368",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02169,
            "epssPercentile": 0.81087,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21369",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02169,
            "epssPercentile": 0.81088,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21371",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02453,
            "epssPercentile": 0.83331,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21373",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00807,
            "epssPercentile": 0.5446,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21375",
            "title": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "summary": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00648,
            "epssPercentile": 0.48786,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21376",
            "title": "Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability",
            "summary": "Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.09389,
            "epssPercentile": 0.95064,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21377",
            "title": "NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "NTLM Hash Disclosure Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.24457,
            "epssPercentile": 0.97722,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21391",
            "title": "Microsoft Windows Storage Link Following Vulnerability",
            "summary": "Microsoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow an attacker to delete data including data that results in the service being unavailable.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-02-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02303,
            "epssPercentile": 0.82202,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-03-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21406",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21407",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21410",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21414",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00612,
            "epssPercentile": 0.47099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21418",
            "title": "Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-02-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01568,
            "epssPercentile": 0.73701,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-03-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21419",
            "title": "Windows Setup Files Cleanup Elevation of Privilege Vulnerability",
            "summary": "Windows Setup Files Cleanup Elevation of Privilege Vulnerability",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0073,
            "epssPercentile": 0.51932,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21420",
            "title": "Windows Disk Cleanup Tool Elevation of Privilege Vulnerability",
            "summary": "Windows Disk Cleanup Tool Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03699,
            "epssPercentile": 0.88996,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-windows-kb5051987",
      "slug": "microsoft-2025-02-windows-kb5051987",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5051987",
      "title": "Deploy Microsoft Windows security update KB5051987",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5051987",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, plus 1 more",
      "platform": "Windows",
      "release_version": "10.0.26100.3194",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21410",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, plus 1 more exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 37 linked CVEs for Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, plus 1 more. Microsoft reports exploitation for CVE-2025-21391, CVE-2025-21418.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 37,
        "ids": [
          "CVE-2025-21179",
          "CVE-2025-21181",
          "CVE-2025-21182",
          "CVE-2025-21183",
          "CVE-2025-21184",
          "CVE-2025-21190",
          "CVE-2025-21200",
          "CVE-2025-21201",
          "CVE-2025-21208",
          "CVE-2025-21212",
          "CVE-2025-21216",
          "CVE-2025-21254",
          "CVE-2025-21337",
          "CVE-2025-21347",
          "CVE-2025-21349",
          "CVE-2025-21350",
          "CVE-2025-21351",
          "CVE-2025-21352",
          "CVE-2025-21358",
          "CVE-2025-21359",
          "CVE-2025-21367",
          "CVE-2025-21368",
          "CVE-2025-21369",
          "CVE-2025-21371",
          "CVE-2025-21373",
          "CVE-2025-21375",
          "CVE-2025-21376",
          "CVE-2025-21377",
          "CVE-2025-21379",
          "CVE-2025-21391",
          "CVE-2025-21406",
          "CVE-2025-21407",
          "CVE-2025-21410",
          "CVE-2025-21414",
          "CVE-2025-21418",
          "CVE-2025-21419",
          "CVE-2025-21420"
        ],
        "details": [
          {
            "id": "CVE-2025-21179",
            "title": "DHCP Client Service Denial of Service Vulnerability",
            "summary": "DHCP Client Service Denial of Service Vulnerability",
            "score": 4.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00747,
            "epssPercentile": 0.52505,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21181",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03511,
            "epssPercentile": 0.88429,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21182",
            "title": "Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability",
            "summary": "Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability",
            "score": 7.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43104,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21183",
            "title": "Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability",
            "summary": "Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability",
            "score": 7.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21184",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0061,
            "epssPercentile": 0.46994,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21190",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21200",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21201",
            "title": "Windows Telephony Server Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Server Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21208",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77412,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21212",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0104,
            "epssPercentile": 0.61739,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21216",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0104,
            "epssPercentile": 0.61739,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21254",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01043,
            "epssPercentile": 0.61852,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21337",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Windows NTFS Elevation of Privilege Vulnerability",
            "score": 3.3,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00613,
            "epssPercentile": 0.47117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21347",
            "title": "Windows Deployment Services Denial of Service Vulnerability",
            "summary": "Windows Deployment Services Denial of Service Vulnerability",
            "score": 6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00661,
            "epssPercentile": 0.49345,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21349",
            "title": "Windows Remote Desktop Configuration Service Tampering Vulnerability",
            "summary": "Windows Remote Desktop Configuration Service Tampering Vulnerability",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0115,
            "epssPercentile": 0.64803,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21350",
            "title": "Windows Kerberos Denial of Service Vulnerability",
            "summary": "Windows Kerberos Denial of Service Vulnerability",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02145,
            "epssPercentile": 0.80877,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21351",
            "title": "Windows Active Directory Domain Services API Denial of Service Vulnerability",
            "summary": "Windows Active Directory Domain Services API Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02495,
            "epssPercentile": 0.83606,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21352",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01043,
            "epssPercentile": 0.61852,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21358",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00766,
            "epssPercentile": 0.53143,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21359",
            "title": "Windows Kernel Security Feature Bypass Vulnerability",
            "summary": "Windows Kernel Security Feature Bypass Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00566,
            "epssPercentile": 0.44897,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21367",
            "title": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "summary": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00648,
            "epssPercentile": 0.48786,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21368",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02169,
            "epssPercentile": 0.81087,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21369",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02169,
            "epssPercentile": 0.81088,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21371",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02453,
            "epssPercentile": 0.83331,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21373",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00807,
            "epssPercentile": 0.5446,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21375",
            "title": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "summary": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00648,
            "epssPercentile": 0.48786,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21376",
            "title": "Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability",
            "summary": "Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.09389,
            "epssPercentile": 0.95064,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21377",
            "title": "NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "NTLM Hash Disclosure Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.24457,
            "epssPercentile": 0.97722,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21379",
            "title": "DHCP Client Service Remote Code Execution Vulnerability",
            "summary": "DHCP Client Service Remote Code Execution Vulnerability",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00915,
            "epssPercentile": 0.57833,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21391",
            "title": "Microsoft Windows Storage Link Following Vulnerability",
            "summary": "Microsoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow an attacker to delete data including data that results in the service being unavailable.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-02-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02303,
            "epssPercentile": 0.82202,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-03-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21406",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21407",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21410",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21414",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00612,
            "epssPercentile": 0.47099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21418",
            "title": "Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-02-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01568,
            "epssPercentile": 0.73701,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-03-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21419",
            "title": "Windows Setup Files Cleanup Elevation of Privilege Vulnerability",
            "summary": "Windows Setup Files Cleanup Elevation of Privilege Vulnerability",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0073,
            "epssPercentile": 0.51932,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21420",
            "title": "Windows Disk Cleanup Tool Elevation of Privilege Vulnerability",
            "summary": "Windows Disk Cleanup Tool Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03699,
            "epssPercentile": 0.88996,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-windows-kb5051989",
      "slug": "microsoft-2025-02-windows-kb5051989",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5051989",
      "title": "Deploy Microsoft Windows security update KB5051989",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5051989",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Windows 11 Version 23H2 for ARM64-based Systems, Windows 11 Version 23H2 for x64-based Systems",
      "platform": "Windows",
      "release_version": "10.0.22631.4890",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21407",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows 11 Version 23H2 for ARM64-based Systems, Windows 11 Version 23H2 for x64-based Systems exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 31 linked CVEs for Windows 11 Version 23H2 for ARM64-based Systems, Windows 11 Version 23H2 for x64-based Systems. Microsoft reports exploitation for CVE-2025-21391, CVE-2025-21418.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 31,
        "ids": [
          "CVE-2025-21181",
          "CVE-2025-21184",
          "CVE-2025-21190",
          "CVE-2025-21200",
          "CVE-2025-21201",
          "CVE-2025-21212",
          "CVE-2025-21216",
          "CVE-2025-21254",
          "CVE-2025-21337",
          "CVE-2025-21347",
          "CVE-2025-21349",
          "CVE-2025-21350",
          "CVE-2025-21351",
          "CVE-2025-21352",
          "CVE-2025-21358",
          "CVE-2025-21359",
          "CVE-2025-21367",
          "CVE-2025-21368",
          "CVE-2025-21369",
          "CVE-2025-21371",
          "CVE-2025-21373",
          "CVE-2025-21375",
          "CVE-2025-21376",
          "CVE-2025-21377",
          "CVE-2025-21391",
          "CVE-2025-21406",
          "CVE-2025-21407",
          "CVE-2025-21414",
          "CVE-2025-21418",
          "CVE-2025-21419",
          "CVE-2025-21420"
        ],
        "details": [
          {
            "id": "CVE-2025-21181",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03511,
            "epssPercentile": 0.88429,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21184",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0061,
            "epssPercentile": 0.46994,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21190",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21200",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21201",
            "title": "Windows Telephony Server Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Server Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21212",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0104,
            "epssPercentile": 0.61739,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21216",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0104,
            "epssPercentile": 0.61739,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21254",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01043,
            "epssPercentile": 0.61852,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21337",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Windows NTFS Elevation of Privilege Vulnerability",
            "score": 3.3,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00613,
            "epssPercentile": 0.47117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21347",
            "title": "Windows Deployment Services Denial of Service Vulnerability",
            "summary": "Windows Deployment Services Denial of Service Vulnerability",
            "score": 6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00661,
            "epssPercentile": 0.49345,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21349",
            "title": "Windows Remote Desktop Configuration Service Tampering Vulnerability",
            "summary": "Windows Remote Desktop Configuration Service Tampering Vulnerability",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0115,
            "epssPercentile": 0.64803,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21350",
            "title": "Windows Kerberos Denial of Service Vulnerability",
            "summary": "Windows Kerberos Denial of Service Vulnerability",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02145,
            "epssPercentile": 0.80877,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21351",
            "title": "Windows Active Directory Domain Services API Denial of Service Vulnerability",
            "summary": "Windows Active Directory Domain Services API Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02495,
            "epssPercentile": 0.83606,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21352",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01043,
            "epssPercentile": 0.61852,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21358",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00766,
            "epssPercentile": 0.53143,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21359",
            "title": "Windows Kernel Security Feature Bypass Vulnerability",
            "summary": "Windows Kernel Security Feature Bypass Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00566,
            "epssPercentile": 0.44897,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21367",
            "title": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "summary": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00648,
            "epssPercentile": 0.48786,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21368",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02169,
            "epssPercentile": 0.81087,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21369",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02169,
            "epssPercentile": 0.81088,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21371",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02453,
            "epssPercentile": 0.83331,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21373",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00807,
            "epssPercentile": 0.5446,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21375",
            "title": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "summary": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00648,
            "epssPercentile": 0.48786,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21376",
            "title": "Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability",
            "summary": "Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.09389,
            "epssPercentile": 0.95064,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21377",
            "title": "NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "NTLM Hash Disclosure Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.24457,
            "epssPercentile": 0.97722,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21391",
            "title": "Microsoft Windows Storage Link Following Vulnerability",
            "summary": "Microsoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow an attacker to delete data including data that results in the service being unavailable.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-02-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02303,
            "epssPercentile": 0.82202,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-03-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21406",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21407",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21414",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00612,
            "epssPercentile": 0.47099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21418",
            "title": "Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-02-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01568,
            "epssPercentile": 0.73701,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-03-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21419",
            "title": "Windows Setup Files Cleanup Elevation of Privilege Vulnerability",
            "summary": "Windows Setup Files Cleanup Elevation of Privilege Vulnerability",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0073,
            "epssPercentile": 0.51932,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21420",
            "title": "Windows Disk Cleanup Tool Elevation of Privilege Vulnerability",
            "summary": "Windows Disk Cleanup Tool Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03699,
            "epssPercentile": 0.88996,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-windows-kb5052000",
      "slug": "microsoft-2025-02-windows-kb5052000",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5052000",
      "title": "Deploy Microsoft Windows security update KB5052000",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5052000",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, plus 1 more",
      "platform": "Windows",
      "release_version": "10.0.17763.6893",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21410",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, plus 1 more exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 33 linked CVEs for Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, plus 1 more. Microsoft reports exploitation for CVE-2025-21391, CVE-2025-21418.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 33,
        "ids": [
          "CVE-2025-21181",
          "CVE-2025-21184",
          "CVE-2025-21190",
          "CVE-2025-21200",
          "CVE-2025-21201",
          "CVE-2025-21208",
          "CVE-2025-21212",
          "CVE-2025-21216",
          "CVE-2025-21254",
          "CVE-2025-21337",
          "CVE-2025-21347",
          "CVE-2025-21349",
          "CVE-2025-21350",
          "CVE-2025-21351",
          "CVE-2025-21352",
          "CVE-2025-21358",
          "CVE-2025-21359",
          "CVE-2025-21367",
          "CVE-2025-21368",
          "CVE-2025-21369",
          "CVE-2025-21371",
          "CVE-2025-21373",
          "CVE-2025-21375",
          "CVE-2025-21376",
          "CVE-2025-21377",
          "CVE-2025-21391",
          "CVE-2025-21406",
          "CVE-2025-21407",
          "CVE-2025-21410",
          "CVE-2025-21414",
          "CVE-2025-21418",
          "CVE-2025-21419",
          "CVE-2025-21420"
        ],
        "details": [
          {
            "id": "CVE-2025-21181",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03511,
            "epssPercentile": 0.88429,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21184",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0061,
            "epssPercentile": 0.46994,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21190",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21200",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21201",
            "title": "Windows Telephony Server Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Server Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21208",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77412,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21212",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0104,
            "epssPercentile": 0.61739,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21216",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0104,
            "epssPercentile": 0.61739,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21254",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01043,
            "epssPercentile": 0.61852,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21337",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Windows NTFS Elevation of Privilege Vulnerability",
            "score": 3.3,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00613,
            "epssPercentile": 0.47117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21347",
            "title": "Windows Deployment Services Denial of Service Vulnerability",
            "summary": "Windows Deployment Services Denial of Service Vulnerability",
            "score": 6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00661,
            "epssPercentile": 0.49345,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21349",
            "title": "Windows Remote Desktop Configuration Service Tampering Vulnerability",
            "summary": "Windows Remote Desktop Configuration Service Tampering Vulnerability",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0115,
            "epssPercentile": 0.64803,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21350",
            "title": "Windows Kerberos Denial of Service Vulnerability",
            "summary": "Windows Kerberos Denial of Service Vulnerability",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02145,
            "epssPercentile": 0.80877,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21351",
            "title": "Windows Active Directory Domain Services API Denial of Service Vulnerability",
            "summary": "Windows Active Directory Domain Services API Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02495,
            "epssPercentile": 0.83606,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21352",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01043,
            "epssPercentile": 0.61852,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21358",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00766,
            "epssPercentile": 0.53143,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21359",
            "title": "Windows Kernel Security Feature Bypass Vulnerability",
            "summary": "Windows Kernel Security Feature Bypass Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00566,
            "epssPercentile": 0.44897,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21367",
            "title": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "summary": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00648,
            "epssPercentile": 0.48786,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21368",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02169,
            "epssPercentile": 0.81087,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21369",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02169,
            "epssPercentile": 0.81088,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21371",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02453,
            "epssPercentile": 0.83331,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21373",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00807,
            "epssPercentile": 0.5446,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21375",
            "title": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "summary": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00648,
            "epssPercentile": 0.48786,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21376",
            "title": "Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability",
            "summary": "Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.09389,
            "epssPercentile": 0.95064,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21377",
            "title": "NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "NTLM Hash Disclosure Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.24457,
            "epssPercentile": 0.97722,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21391",
            "title": "Microsoft Windows Storage Link Following Vulnerability",
            "summary": "Microsoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow an attacker to delete data including data that results in the service being unavailable.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-02-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02303,
            "epssPercentile": 0.82202,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-03-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21406",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21407",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21410",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21414",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00612,
            "epssPercentile": 0.47099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21418",
            "title": "Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-02-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01568,
            "epssPercentile": 0.73701,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-03-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21419",
            "title": "Windows Setup Files Cleanup Elevation of Privilege Vulnerability",
            "summary": "Windows Setup Files Cleanup Elevation of Privilege Vulnerability",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0073,
            "epssPercentile": 0.51932,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21420",
            "title": "Windows Disk Cleanup Tool Elevation of Privilege Vulnerability",
            "summary": "Windows Disk Cleanup Tool Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03699,
            "epssPercentile": 0.88996,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-windows-kb5052006",
      "slug": "microsoft-2025-02-windows-kb5052006",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5052006",
      "title": "Deploy Microsoft Windows security update KB5052006",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5052006",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Windows 10 Version 1607 for 32-bit Systems, Windows 10 Version 1607 for x64-based Systems, Windows Server 2016, plus 1 more",
      "platform": "Windows",
      "release_version": "10.0.14393.7785",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21410",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows 10 Version 1607 for 32-bit Systems, Windows 10 Version 1607 for x64-based Systems, Windows Server 2016, plus 1 more exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 32 linked CVEs for Windows 10 Version 1607 for 32-bit Systems, Windows 10 Version 1607 for x64-based Systems, Windows Server 2016, plus 1 more. Microsoft reports exploitation for CVE-2025-21391, CVE-2025-21418.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 32,
        "ids": [
          "CVE-2025-21181",
          "CVE-2025-21184",
          "CVE-2025-21190",
          "CVE-2025-21200",
          "CVE-2025-21201",
          "CVE-2025-21208",
          "CVE-2025-21212",
          "CVE-2025-21216",
          "CVE-2025-21254",
          "CVE-2025-21337",
          "CVE-2025-21347",
          "CVE-2025-21349",
          "CVE-2025-21350",
          "CVE-2025-21351",
          "CVE-2025-21352",
          "CVE-2025-21358",
          "CVE-2025-21359",
          "CVE-2025-21368",
          "CVE-2025-21369",
          "CVE-2025-21371",
          "CVE-2025-21373",
          "CVE-2025-21375",
          "CVE-2025-21376",
          "CVE-2025-21377",
          "CVE-2025-21391",
          "CVE-2025-21406",
          "CVE-2025-21407",
          "CVE-2025-21410",
          "CVE-2025-21414",
          "CVE-2025-21418",
          "CVE-2025-21419",
          "CVE-2025-21420"
        ],
        "details": [
          {
            "id": "CVE-2025-21181",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03511,
            "epssPercentile": 0.88429,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21184",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0061,
            "epssPercentile": 0.46994,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21190",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21200",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21201",
            "title": "Windows Telephony Server Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Server Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21208",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77412,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21212",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0104,
            "epssPercentile": 0.61739,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21216",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0104,
            "epssPercentile": 0.61739,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21254",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01043,
            "epssPercentile": 0.61852,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21337",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Windows NTFS Elevation of Privilege Vulnerability",
            "score": 3.3,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00613,
            "epssPercentile": 0.47117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21347",
            "title": "Windows Deployment Services Denial of Service Vulnerability",
            "summary": "Windows Deployment Services Denial of Service Vulnerability",
            "score": 6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00661,
            "epssPercentile": 0.49345,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21349",
            "title": "Windows Remote Desktop Configuration Service Tampering Vulnerability",
            "summary": "Windows Remote Desktop Configuration Service Tampering Vulnerability",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0115,
            "epssPercentile": 0.64803,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21350",
            "title": "Windows Kerberos Denial of Service Vulnerability",
            "summary": "Windows Kerberos Denial of Service Vulnerability",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02145,
            "epssPercentile": 0.80877,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21351",
            "title": "Windows Active Directory Domain Services API Denial of Service Vulnerability",
            "summary": "Windows Active Directory Domain Services API Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02495,
            "epssPercentile": 0.83606,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21352",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01043,
            "epssPercentile": 0.61852,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21358",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00766,
            "epssPercentile": 0.53143,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21359",
            "title": "Windows Kernel Security Feature Bypass Vulnerability",
            "summary": "Windows Kernel Security Feature Bypass Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00566,
            "epssPercentile": 0.44897,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21368",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02169,
            "epssPercentile": 0.81087,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21369",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02169,
            "epssPercentile": 0.81088,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21371",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02453,
            "epssPercentile": 0.83331,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21373",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00807,
            "epssPercentile": 0.5446,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21375",
            "title": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "summary": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00648,
            "epssPercentile": 0.48786,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21376",
            "title": "Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability",
            "summary": "Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.09389,
            "epssPercentile": 0.95064,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21377",
            "title": "NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "NTLM Hash Disclosure Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.24457,
            "epssPercentile": 0.97722,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21391",
            "title": "Microsoft Windows Storage Link Following Vulnerability",
            "summary": "Microsoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow an attacker to delete data including data that results in the service being unavailable.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-02-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02303,
            "epssPercentile": 0.82202,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-03-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21406",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21407",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21410",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21414",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00612,
            "epssPercentile": 0.47099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21418",
            "title": "Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-02-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01568,
            "epssPercentile": 0.73701,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-03-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21419",
            "title": "Windows Setup Files Cleanup Elevation of Privilege Vulnerability",
            "summary": "Windows Setup Files Cleanup Elevation of Privilege Vulnerability",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0073,
            "epssPercentile": 0.51932,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21420",
            "title": "Windows Disk Cleanup Tool Elevation of Privilege Vulnerability",
            "summary": "Windows Disk Cleanup Tool Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03699,
            "epssPercentile": 0.88996,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-windows-kb5052040",
      "slug": "microsoft-2025-02-windows-kb5052040",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5052040",
      "title": "Deploy Microsoft Windows security update KB5052040",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5052040",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Windows 10 for 32-bit Systems, Windows 10 for x64-based Systems",
      "platform": "Windows",
      "release_version": "10.0.10240.20915",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21407",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows 10 for 32-bit Systems, Windows 10 for x64-based Systems exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 26 linked CVEs for Windows 10 for 32-bit Systems, Windows 10 for x64-based Systems. Microsoft reports exploitation for CVE-2025-21391, CVE-2025-21418.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 26,
        "ids": [
          "CVE-2025-21181",
          "CVE-2025-21184",
          "CVE-2025-21190",
          "CVE-2025-21200",
          "CVE-2025-21201",
          "CVE-2025-21337",
          "CVE-2025-21347",
          "CVE-2025-21349",
          "CVE-2025-21350",
          "CVE-2025-21352",
          "CVE-2025-21358",
          "CVE-2025-21359",
          "CVE-2025-21368",
          "CVE-2025-21369",
          "CVE-2025-21371",
          "CVE-2025-21373",
          "CVE-2025-21375",
          "CVE-2025-21376",
          "CVE-2025-21377",
          "CVE-2025-21391",
          "CVE-2025-21406",
          "CVE-2025-21407",
          "CVE-2025-21414",
          "CVE-2025-21418",
          "CVE-2025-21419",
          "CVE-2025-21420"
        ],
        "details": [
          {
            "id": "CVE-2025-21181",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03511,
            "epssPercentile": 0.88429,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21184",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0061,
            "epssPercentile": 0.46994,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21190",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21200",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21201",
            "title": "Windows Telephony Server Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Server Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21337",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Windows NTFS Elevation of Privilege Vulnerability",
            "score": 3.3,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00613,
            "epssPercentile": 0.47117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21347",
            "title": "Windows Deployment Services Denial of Service Vulnerability",
            "summary": "Windows Deployment Services Denial of Service Vulnerability",
            "score": 6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00661,
            "epssPercentile": 0.49345,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21349",
            "title": "Windows Remote Desktop Configuration Service Tampering Vulnerability",
            "summary": "Windows Remote Desktop Configuration Service Tampering Vulnerability",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0115,
            "epssPercentile": 0.64803,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21350",
            "title": "Windows Kerberos Denial of Service Vulnerability",
            "summary": "Windows Kerberos Denial of Service Vulnerability",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02145,
            "epssPercentile": 0.80877,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21352",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01043,
            "epssPercentile": 0.61852,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21358",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00766,
            "epssPercentile": 0.53143,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21359",
            "title": "Windows Kernel Security Feature Bypass Vulnerability",
            "summary": "Windows Kernel Security Feature Bypass Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00566,
            "epssPercentile": 0.44897,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21368",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02169,
            "epssPercentile": 0.81087,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21369",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02169,
            "epssPercentile": 0.81088,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21371",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02453,
            "epssPercentile": 0.83331,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21373",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00807,
            "epssPercentile": 0.5446,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21375",
            "title": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "summary": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00648,
            "epssPercentile": 0.48786,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21376",
            "title": "Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability",
            "summary": "Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.09389,
            "epssPercentile": 0.95064,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21377",
            "title": "NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "NTLM Hash Disclosure Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.24457,
            "epssPercentile": 0.97722,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21391",
            "title": "Microsoft Windows Storage Link Following Vulnerability",
            "summary": "Microsoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow an attacker to delete data including data that results in the service being unavailable.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-02-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02303,
            "epssPercentile": 0.82202,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-03-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21406",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21407",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21414",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00612,
            "epssPercentile": 0.47099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21418",
            "title": "Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-02-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01568,
            "epssPercentile": 0.73701,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-03-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21419",
            "title": "Windows Setup Files Cleanup Elevation of Privilege Vulnerability",
            "summary": "Windows Setup Files Cleanup Elevation of Privilege Vulnerability",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0073,
            "epssPercentile": 0.51932,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21420",
            "title": "Windows Disk Cleanup Tool Elevation of Privilege Vulnerability",
            "summary": "Windows Disk Cleanup Tool Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03699,
            "epssPercentile": 0.88996,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-windows-kb5052105",
      "slug": "microsoft-2025-02-windows-kb5052105",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5052105",
      "title": "Deploy Microsoft Windows security update KB5052105",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5052105",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, plus 1 more",
      "platform": "Windows",
      "release_version": "10.0.26100.3107",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21410",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, plus 1 more exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 37 linked CVEs for Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, plus 1 more. Microsoft reports exploitation for CVE-2025-21391, CVE-2025-21418.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 37,
        "ids": [
          "CVE-2025-21179",
          "CVE-2025-21181",
          "CVE-2025-21182",
          "CVE-2025-21183",
          "CVE-2025-21184",
          "CVE-2025-21190",
          "CVE-2025-21200",
          "CVE-2025-21201",
          "CVE-2025-21208",
          "CVE-2025-21212",
          "CVE-2025-21216",
          "CVE-2025-21254",
          "CVE-2025-21337",
          "CVE-2025-21347",
          "CVE-2025-21349",
          "CVE-2025-21350",
          "CVE-2025-21351",
          "CVE-2025-21352",
          "CVE-2025-21358",
          "CVE-2025-21359",
          "CVE-2025-21367",
          "CVE-2025-21368",
          "CVE-2025-21369",
          "CVE-2025-21371",
          "CVE-2025-21373",
          "CVE-2025-21375",
          "CVE-2025-21376",
          "CVE-2025-21377",
          "CVE-2025-21379",
          "CVE-2025-21391",
          "CVE-2025-21406",
          "CVE-2025-21407",
          "CVE-2025-21410",
          "CVE-2025-21414",
          "CVE-2025-21418",
          "CVE-2025-21419",
          "CVE-2025-21420"
        ],
        "details": [
          {
            "id": "CVE-2025-21179",
            "title": "DHCP Client Service Denial of Service Vulnerability",
            "summary": "DHCP Client Service Denial of Service Vulnerability",
            "score": 4.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00747,
            "epssPercentile": 0.52505,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21181",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03511,
            "epssPercentile": 0.88429,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21182",
            "title": "Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability",
            "summary": "Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability",
            "score": 7.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43104,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21183",
            "title": "Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability",
            "summary": "Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability",
            "score": 7.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43105,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21184",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0061,
            "epssPercentile": 0.46994,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21190",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21200",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21201",
            "title": "Windows Telephony Server Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Server Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21208",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77412,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21212",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0104,
            "epssPercentile": 0.61739,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21216",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0104,
            "epssPercentile": 0.61739,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21254",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01043,
            "epssPercentile": 0.61852,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21337",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Windows NTFS Elevation of Privilege Vulnerability",
            "score": 3.3,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00613,
            "epssPercentile": 0.47117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21347",
            "title": "Windows Deployment Services Denial of Service Vulnerability",
            "summary": "Windows Deployment Services Denial of Service Vulnerability",
            "score": 6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00661,
            "epssPercentile": 0.49345,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21349",
            "title": "Windows Remote Desktop Configuration Service Tampering Vulnerability",
            "summary": "Windows Remote Desktop Configuration Service Tampering Vulnerability",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0115,
            "epssPercentile": 0.64803,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21350",
            "title": "Windows Kerberos Denial of Service Vulnerability",
            "summary": "Windows Kerberos Denial of Service Vulnerability",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02145,
            "epssPercentile": 0.80877,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21351",
            "title": "Windows Active Directory Domain Services API Denial of Service Vulnerability",
            "summary": "Windows Active Directory Domain Services API Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02495,
            "epssPercentile": 0.83606,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21352",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01043,
            "epssPercentile": 0.61852,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21358",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00766,
            "epssPercentile": 0.53143,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21359",
            "title": "Windows Kernel Security Feature Bypass Vulnerability",
            "summary": "Windows Kernel Security Feature Bypass Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00566,
            "epssPercentile": 0.44897,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21367",
            "title": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "summary": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00648,
            "epssPercentile": 0.48786,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21368",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02169,
            "epssPercentile": 0.81087,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21369",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02169,
            "epssPercentile": 0.81088,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21371",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02453,
            "epssPercentile": 0.83331,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21373",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00807,
            "epssPercentile": 0.5446,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21375",
            "title": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "summary": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00648,
            "epssPercentile": 0.48786,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21376",
            "title": "Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability",
            "summary": "Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.09389,
            "epssPercentile": 0.95064,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21377",
            "title": "NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "NTLM Hash Disclosure Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.24457,
            "epssPercentile": 0.97722,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21379",
            "title": "DHCP Client Service Remote Code Execution Vulnerability",
            "summary": "DHCP Client Service Remote Code Execution Vulnerability",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00915,
            "epssPercentile": 0.57833,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21391",
            "title": "Microsoft Windows Storage Link Following Vulnerability",
            "summary": "Microsoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow an attacker to delete data including data that results in the service being unavailable.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-02-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02303,
            "epssPercentile": 0.82202,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-03-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21406",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21407",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21410",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21414",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00612,
            "epssPercentile": 0.47099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21418",
            "title": "Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-02-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01568,
            "epssPercentile": 0.73701,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-03-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21419",
            "title": "Windows Setup Files Cleanup Elevation of Privilege Vulnerability",
            "summary": "Windows Setup Files Cleanup Elevation of Privilege Vulnerability",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0073,
            "epssPercentile": 0.51932,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21420",
            "title": "Windows Disk Cleanup Tool Elevation of Privilege Vulnerability",
            "summary": "Windows Disk Cleanup Tool Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03699,
            "epssPercentile": 0.88996,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-02-windows-kb5052106",
      "slug": "microsoft-2025-02-windows-kb5052106",
      "cycle_id": "2025-02",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5052106",
      "title": "Deploy Microsoft Windows security update KB5052106",
      "source_title": "2025-02 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5052106",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "Windows Server 2022, Windows Server 2022 (Server Core installation)",
      "platform": "Windows",
      "release_version": "10.0.20348.3148",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21410",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows Server 2022, Windows Server 2022 (Server Core installation) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 33 linked CVEs for Windows Server 2022, Windows Server 2022 (Server Core installation). Microsoft reports exploitation for CVE-2025-21391, CVE-2025-21418.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 33,
        "ids": [
          "CVE-2025-21181",
          "CVE-2025-21184",
          "CVE-2025-21190",
          "CVE-2025-21200",
          "CVE-2025-21201",
          "CVE-2025-21208",
          "CVE-2025-21212",
          "CVE-2025-21216",
          "CVE-2025-21254",
          "CVE-2025-21337",
          "CVE-2025-21347",
          "CVE-2025-21349",
          "CVE-2025-21350",
          "CVE-2025-21351",
          "CVE-2025-21352",
          "CVE-2025-21358",
          "CVE-2025-21359",
          "CVE-2025-21367",
          "CVE-2025-21368",
          "CVE-2025-21369",
          "CVE-2025-21371",
          "CVE-2025-21373",
          "CVE-2025-21375",
          "CVE-2025-21376",
          "CVE-2025-21377",
          "CVE-2025-21391",
          "CVE-2025-21406",
          "CVE-2025-21407",
          "CVE-2025-21410",
          "CVE-2025-21414",
          "CVE-2025-21418",
          "CVE-2025-21419",
          "CVE-2025-21420"
        ],
        "details": [
          {
            "id": "CVE-2025-21181",
            "title": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "summary": "Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03511,
            "epssPercentile": 0.88429,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21184",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0061,
            "epssPercentile": 0.46994,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21190",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21200",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21201",
            "title": "Windows Telephony Server Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Server Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77411,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21208",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01827,
            "epssPercentile": 0.77412,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21212",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0104,
            "epssPercentile": 0.61739,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21216",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0104,
            "epssPercentile": 0.61739,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21254",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01043,
            "epssPercentile": 0.61852,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21337",
            "title": "Windows NTFS Elevation of Privilege Vulnerability",
            "summary": "Windows NTFS Elevation of Privilege Vulnerability",
            "score": 3.3,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00613,
            "epssPercentile": 0.47117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21347",
            "title": "Windows Deployment Services Denial of Service Vulnerability",
            "summary": "Windows Deployment Services Denial of Service Vulnerability",
            "score": 6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00661,
            "epssPercentile": 0.49345,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21349",
            "title": "Windows Remote Desktop Configuration Service Tampering Vulnerability",
            "summary": "Windows Remote Desktop Configuration Service Tampering Vulnerability",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0115,
            "epssPercentile": 0.64803,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21350",
            "title": "Windows Kerberos Denial of Service Vulnerability",
            "summary": "Windows Kerberos Denial of Service Vulnerability",
            "score": 5.9,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02145,
            "epssPercentile": 0.80877,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21351",
            "title": "Windows Active Directory Domain Services API Denial of Service Vulnerability",
            "summary": "Windows Active Directory Domain Services API Denial of Service Vulnerability",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02495,
            "epssPercentile": 0.83606,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21352",
            "title": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "summary": "Internet Connection Sharing (ICS) Denial of Service Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01043,
            "epssPercentile": 0.61852,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21358",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00766,
            "epssPercentile": 0.53143,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21359",
            "title": "Windows Kernel Security Feature Bypass Vulnerability",
            "summary": "Windows Kernel Security Feature Bypass Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00566,
            "epssPercentile": 0.44897,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21367",
            "title": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "summary": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00648,
            "epssPercentile": 0.48786,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21368",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02169,
            "epssPercentile": 0.81087,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21369",
            "title": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "summary": "Microsoft Digest Authentication Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02169,
            "epssPercentile": 0.81088,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21371",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02453,
            "epssPercentile": 0.83331,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21373",
            "title": "Windows Installer Elevation of Privilege Vulnerability",
            "summary": "Windows Installer Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00807,
            "epssPercentile": 0.5446,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21375",
            "title": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "summary": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00648,
            "epssPercentile": 0.48786,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21376",
            "title": "Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability",
            "summary": "Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.09389,
            "epssPercentile": 0.95064,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21377",
            "title": "NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "NTLM Hash Disclosure Spoofing Vulnerability",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.24457,
            "epssPercentile": 0.97722,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21391",
            "title": "Microsoft Windows Storage Link Following Vulnerability",
            "summary": "Microsoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow an attacker to delete data including data that results in the service being unavailable.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-02-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02303,
            "epssPercentile": 0.82202,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-03-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21406",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21407",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Windows Telephony Service Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21410",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01833,
            "epssPercentile": 0.77485,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21414",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00612,
            "epssPercentile": 0.47099,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21418",
            "title": "Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-02-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01568,
            "epssPercentile": 0.73701,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-03-04 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21419",
            "title": "Windows Setup Files Cleanup Elevation of Privilege Vulnerability",
            "summary": "Windows Setup Files Cleanup Elevation of Privilege Vulnerability",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0073,
            "epssPercentile": 0.51932,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21420",
            "title": "Windows Disk Cleanup Tool Elevation of Privilege Vulnerability",
            "summary": "Windows Disk Cleanup Tool Elevation of Privilege Vulnerability",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03699,
            "epssPercentile": 0.88996,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-02-3287784",
      "slug": "sap-2025-02-3287784",
      "cycle_id": "2025-02",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3287784",
      "title": "Assess and apply SAP security advisory 3287784",
      "source_title": "Update to Security Note released on April 2023 Patch Day: [CVE-2023-24527] Improper Access Control in SAP NetWeaver AS Java for Deploy Service Product- SAP NetWeaver AS Java for Deploy Service, Version – ENGINEAPI 7.50, SERVERCORE 7.50",
      "source_url": "https://me.sap.com/notes/3287784",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "revised",
      "product": "SAP NetWeaver AS Java for Deploy Service, Version – ENGINEAPI 7.50, SERVERCORE 7.50",
      "platform": "SAP",
      "release_version": "ENGINEAPI 7.50, SERVERCORE 7.50",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 5.3",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 5.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2023-24527",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP NetWeaver AS Java for Deploy Service, Version – ENGINEAPI 7.50, SERVERCORE 7.50 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3287784 in its 2025-02 Security Patch Day release for SAP NetWeaver AS Java for Deploy Service, Version – ENGINEAPI 7.50, SERVERCORE 7.50. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2023-24527"
        ],
        "details": [
          {
            "id": "CVE-2023-24527",
            "title": "Improper Access Control in SAP NetWeaver AS Java for Deploy Service",
            "summary": "SAP NetWeaver AS Java for Deploy Service - version 7.5, does not perform any access control checks for functionalities that require user identity enabling an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to access a service which will enable them to access but not modify server settings and data with no effect on availability and integrity.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00452,
            "epssPercentile": 0.37847,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-02-3417627",
      "slug": "sap-2025-02-3417627",
      "cycle_id": "2025-02",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3417627",
      "title": "Assess and apply SAP security advisory 3417627",
      "source_title": "Update to Security Note released on February 2024 Patch Day: [CVE-2024-22126] Cross Site Scripting vulnerability in NetWeaver AS Java (User Admin Application) Product- SAP NetWeaver AS Java (User Admin Application), Version – 7.50",
      "source_url": "https://me.sap.com/notes/3417627",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "revised",
      "product": "SAP NetWeaver AS Java (User Admin Application), Version – 7.50",
      "platform": "SAP",
      "release_version": "7.50",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "High; CVSS 8.8",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 6.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2024-22126",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP NetWeaver AS Java (User Admin Application), Version – 7.50 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3417627 in its 2025-02 Security Patch Day release for SAP NetWeaver AS Java (User Admin Application), Version – 7.50. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2024-22126"
        ],
        "details": [
          {
            "id": "CVE-2024-22126",
            "title": "Cross Site Scripting vulnerability in SAP NetWeaver AS Java (User Admin Application)",
            "summary": "The User Admin application of SAP NetWeaver AS for Java - version 7.50, insufficiently validates and improperly encodes the incoming URL parameters before including them into the redirect URL. This results in Cross-Site Scripting (XSS) vulnerability, leading to a high impact on confidentiality and mild impact on integrity and availability.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00519,
            "epssPercentile": 0.42244,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-02-3426825",
      "slug": "sap-2025-02-3426825",
      "cycle_id": "2025-02",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3426825",
      "title": "Assess and apply SAP security advisory 3426825",
      "source_title": "[CVE-2025-23191] Cache Poisoning through header manipulation vulnerability in SAP Fiori for SAP ERP | Product - SAP Fiori for SAP ERP, Version - SAP_GWFND 740, 750, 751, 752, 753, 754, 755, 756, 757, 758",
      "source_url": "https://me.sap.com/notes/3426825",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "SAP Fiori for SAP ERP, Version - SAP_GWFND 740, 750, 751, 752, 753, 754, 755, 756, 757, 758",
      "platform": "SAP",
      "release_version": "SAP_GWFND 740, 750, 751, 752, 753, 754, 755, 756, 757, 758",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Low; CVSS 3.1",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 3.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-23191",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP Fiori for SAP ERP, Version - SAP_GWFND 740, 750, 751, 752, 753, 754, 755, 756, 757, 758 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3426825 in its 2025-02 Security Patch Day release for SAP Fiori for SAP ERP, Version - SAP_GWFND 740, 750, 751, 752, 753, 754, 755, 756, 757, 758. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-23191"
        ],
        "details": [
          {
            "id": "CVE-2025-23191",
            "title": "Cache Poisoning through header manipulation vulnerability in SAP Fiori for SAP ERP",
            "summary": "Cached values belonging to the SAP OData endpoint in SAP Fiori for SAP ERP could be poisoned by modifying the Host header value in an HTTP GET request. An attacker could alter the `atom:link` values in the returned metadata redirecting them from the SAP server to a malicious link set by the attacker. Successful exploitation could cause low impact on integrity of the application.",
            "score": 3.1,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00248,
            "epssPercentile": 0.16058,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-02-3445708",
      "slug": "sap-2025-02-3445708",
      "cycle_id": "2025-02",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3445708",
      "title": "Assess and apply SAP security advisory 3445708",
      "source_title": "[CVE-2025-24867] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence platform (BI Launchpad) Product- SAP BusinessObjects Platform (BI Launchpad), Version – ENTERPRISE 430, 2025",
      "source_url": "https://me.sap.com/notes/3445708",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "SAP BusinessObjects Platform (BI Launchpad), Version – ENTERPRISE 430, 2025",
      "platform": "SAP",
      "release_version": "ENTERPRISE 430, 2025",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 6.1",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 6.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-24867",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP BusinessObjects Platform (BI Launchpad), Version – ENTERPRISE 430, 2025 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3445708 in its 2025-02 Security Patch Day release for SAP BusinessObjects Platform (BI Launchpad), Version – ENTERPRISE 430, 2025. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-24867"
        ],
        "details": [
          {
            "id": "CVE-2025-24867",
            "title": "Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence platform (BI Launchpad)",
            "summary": "SAP BusinessObjects Platform (BI Launchpad) does not sufficiently handle user input, resulting in Cross-Site Scripting (XSS) vulnerability. The application allows an unauthenticated attacker to craft a URL that embeds a malicious script within an unprotected parameter. When a victim clicks the link, the script will be executed in the browser, giving the attacker the ability to access and/or modify information related",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0026,
            "epssPercentile": 0.17619,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-02-3525794",
      "slug": "sap-2025-02-3525794",
      "cycle_id": "2025-02",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3525794",
      "title": "Assess and apply SAP security advisory 3525794",
      "source_title": "[CVE-2025-0064] Improper Authorization in SAP BusinessObjects Business Intelligence platform (Central Management Console) Product- SAP BusinessObjects Business Intelligence platform (Central Management Console), Versions – ENTERPRISE 430, 2025",
      "source_url": "https://me.sap.com/notes/3525794",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "SAP BusinessObjects Business Intelligence platform (Central Management Console), Versions – ENTERPRISE 430, 2025",
      "platform": "SAP",
      "release_version": "s – ENTERPRISE 430, 2025",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "High; CVSS 8.7",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.7,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-0064",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP BusinessObjects Business Intelligence platform (Central Management Console), Versions – ENTERPRISE 430, 2025 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3525794 in its 2025-02 Security Patch Day release for SAP BusinessObjects Business Intelligence platform (Central Management Console), Versions – ENTERPRISE 430, 2025. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-0064"
        ],
        "details": [
          {
            "id": "CVE-2025-0064",
            "title": "Improper Authorization in SAP BusinessObjects Business Intelligence platform (Central Management Console)",
            "summary": "Under specific conditions, the Central Management Console of the SAP BusinessObjects Business Intelligence platform allows an attacker with admin rights to generate or retrieve a secret passphrase, enabling them to impersonate any user in the system. This results in a high impact on confidentiality and integrity, with no impact on availability.",
            "score": 8.7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00376,
            "epssPercentile": 0.3075,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-02-3526203",
      "slug": "sap-2025-02-3526203",
      "cycle_id": "2025-02",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3526203",
      "title": "Assess and apply SAP security advisory 3526203",
      "source_title": "[CVE-2025-0054] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server Java Product- SAP NetWeaver Application Server Java, Versions – EP-BASIS 7.50, FRAMEWORK-EXT 7.50",
      "source_url": "https://me.sap.com/notes/3526203",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "SAP NetWeaver Application Server Java, Versions – EP-BASIS 7.50, FRAMEWORK-EXT 7.50",
      "platform": "SAP",
      "release_version": "s – EP-BASIS 7.50, FRAMEWORK-EXT 7.50",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 5.4",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 5.4,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-0054",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP NetWeaver Application Server Java, Versions – EP-BASIS 7.50, FRAMEWORK-EXT 7.50 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3526203 in its 2025-02 Security Patch Day release for SAP NetWeaver Application Server Java, Versions – EP-BASIS 7.50, FRAMEWORK-EXT 7.50. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-0054"
        ],
        "details": [
          {
            "id": "CVE-2025-0054",
            "title": "Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server Java",
            "summary": "SAP NetWeaver Application Server Java does not sufficiently handle user input, resulting in a stored cross-site scripting vulnerability. The application allows attackers with basic user privileges to store a Javascript payload on the server, which could be later executed in the victim's web browser. With this the attacker might be able to read or modify information associated with the vulnerable web page.",
            "score": 5.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00274,
            "epssPercentile": 0.19518,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-02-3532025",
      "slug": "sap-2025-02-3532025",
      "cycle_id": "2025-02",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3532025",
      "title": "Assess and apply SAP security advisory 3532025",
      "source_title": "[CVE-2025-25241] Missing Authorization check in SAP Fiori Apps Reference Library (My Overtime Requests) Product- SAP Fiori Apps Reference Library (My Overtime Requests), Version – GBX01HR5 605",
      "source_url": "https://me.sap.com/notes/3532025",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "SAP Fiori Apps Reference Library (My Overtime Requests), Version – GBX01HR5 605",
      "platform": "SAP",
      "release_version": "GBX01HR5 605",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 5.4",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 5.4,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-25241",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP Fiori Apps Reference Library (My Overtime Requests), Version – GBX01HR5 605 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3532025 in its 2025-02 Security Patch Day release for SAP Fiori Apps Reference Library (My Overtime Requests), Version – GBX01HR5 605. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-25241"
        ],
        "details": [
          {
            "id": "CVE-2025-25241",
            "title": "Missing Authorization check in SAP Fiori Apps Reference Library (My Overtime Requests)",
            "summary": "Due to a missing authorization check, an attacker who is logged in to application can view/ delete �My Overtime Requests� which could allow the attacker to access employee information. This leads to low impact on confidentiality, integrity of the application. There is no impact on availability.",
            "score": 5.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00221,
            "epssPercentile": 0.1255,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-02-3540273",
      "slug": "sap-2025-02-3540273",
      "cycle_id": "2025-02",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3540273",
      "title": "Assess and apply SAP security advisory 3540273",
      "source_title": "Multiple vulnerabilities in Apache Solr within SAP Commerce Cloud Related CVEs - CVE-2024-45216, CVE-2024-45217 | Product - SAP Commerce Cloud, Versions – HY_COM 2205, COM_CLOUD 2211",
      "source_url": "https://me.sap.com/notes/3540273",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "SAP Commerce Cloud, Versions – HY_COM 2205, COM_CLOUD 2211",
      "platform": "SAP",
      "release_version": "s – HY_COM 2205, COM_CLOUD 2211",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 5.5",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 9.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2024-45216",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP Commerce Cloud, Versions – HY_COM 2205, COM_CLOUD 2211 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3540273 in its 2025-02 Security Patch Day release for SAP Commerce Cloud, Versions – HY_COM 2205, COM_CLOUD 2211. The public bulletin links 2 CVEs; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 2,
        "ids": [
          "CVE-2024-45216",
          "CVE-2024-45217"
        ],
        "details": [
          {
            "id": "CVE-2024-45216",
            "title": "Apache Solr: Authentication bypass possible using a fake URL Path ending",
            "summary": "Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authentication is used, are vulnerable to Authentication bypass. A fake ending at the end of any Solr API URL path, will allow requests to skip Authentication while maintaining the API contract with the original URL Path. This fake ending looks like an unprotected API path, how",
            "score": 9.8,
            "version": "3.1",
            "severity": "Critical",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.91714,
            "epssPercentile": 0.99808,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 72 hours",
            "urgencyReason": "Critical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.",
            "confidence": "High"
          },
          {
            "id": "CVE-2024-45217",
            "title": "Apache Solr: ConfigSets created during a backup restore command are trusted implicitly",
            "summary": "Insecure Default Initialization of Resource vulnerability in Apache Solr. New ConfigSets that are created via a Restore command, which copy a configSet from the backup and give it a new name, are created without setting the \"trusted\" metadata. ConfigSets that do not contain the flag are trusted implicitly if the metadata is missing, therefore this leads to \"trusted\" ConfigSets that may not have been created with an A",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CISA ADP",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00742,
            "epssPercentile": 0.52338,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-02-3546470",
      "slug": "sap-2025-02-3546470",
      "cycle_id": "2025-02",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3546470",
      "title": "Assess and apply SAP security advisory 3546470",
      "source_title": "[CVE-2025-23187] Missing Authorization Check in SAP NetWeaver and ABAP Platform (SDCCN) Related CVE - CVE-2025-23189 Product- SAP NetWeaver and ABAP Platform (SDCCN), Versions – ST-PI 2008_1_700, ST-PI 2008_1_710, ST-PI 740",
      "source_url": "https://me.sap.com/notes/3546470",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "SAP NetWeaver and ABAP Platform (SDCCN), Versions – ST-PI 2008_1_700, ST-PI 2008_1_710, ST-PI 740",
      "platform": "SAP",
      "release_version": "s – ST-PI 2008_1_700, ST-PI 2008_1_710, ST-PI 740",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 5.3",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 5.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-23187",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP NetWeaver and ABAP Platform (SDCCN), Versions – ST-PI 2008_1_700, ST-PI 2008_1_710, ST-PI 740 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3546470 in its 2025-02 Security Patch Day release for SAP NetWeaver and ABAP Platform (SDCCN), Versions – ST-PI 2008_1_700, ST-PI 2008_1_710, ST-PI 740. The public bulletin links 2 CVEs; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 2,
        "ids": [
          "CVE-2025-23187",
          "CVE-2025-23189"
        ],
        "details": [
          {
            "id": "CVE-2025-23187",
            "title": "Missing Authorization Check in SAP NetWeaver and ABAP Platform (SDCCN)",
            "summary": "Due to missing authorization check in an RFC enabled function module in transaction SDCCN, an unauthenticated attacker could generate technical meta-data. This leads to a low impact on integrity. There is no impact on confidentiality or availability.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00285,
            "epssPercentile": 0.20682,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-23189",
            "title": "Missing Authorization Check in SAP NetWeaver and ABAP Platform (SDCCN)",
            "summary": "Due to missing authorization check in an RFC enabled function module in transaction SDCCN, an authenticated attacker could generate technical meta-data. This leads to a low impact on integrity. There is no impact on confidentiality or availability",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00244,
            "epssPercentile": 0.15495,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-02-3547581",
      "slug": "sap-2025-02-3547581",
      "cycle_id": "2025-02",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3547581",
      "title": "Assess and apply SAP security advisory 3547581",
      "source_title": "[CVE-2025-23190] Missing Authorization check in SAP NetWeaver and ABAP platform (ST-PI) | Product - SAP NetWeaver and ABAP platform (ST-PI), Version - ST-PI 2008_1_700, ST-PI 2008_1_710, ST-PI 740",
      "source_url": "https://me.sap.com/notes/3547581",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "SAP NetWeaver and ABAP platform (ST-PI), Version - ST-PI 2008_1_700, ST-PI 2008_1_710, ST-PI 740",
      "platform": "SAP",
      "release_version": "ST-PI 2008_1_700, ST-PI 2008_1_710, ST-PI 740",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 4.3",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 4.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-23190",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP NetWeaver and ABAP platform (ST-PI), Version - ST-PI 2008_1_700, ST-PI 2008_1_710, ST-PI 740 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3547581 in its 2025-02 Security Patch Day release for SAP NetWeaver and ABAP platform (ST-PI), Version - ST-PI 2008_1_700, ST-PI 2008_1_710, ST-PI 740. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-23190"
        ],
        "details": [
          {
            "id": "CVE-2025-23190",
            "title": "Missing Authorization check in SAP NetWeaver and ABAP platform (ST-PI)",
            "summary": "Due to missing authorization check, an authenticated attacker could call a remote-enabled function module which allows them to access data that they would otherwise not have access to. The attacker cannot modify data or impact the availability of the system.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00259,
            "epssPercentile": 0.17469,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-02-3550027",
      "slug": "sap-2025-02-3550027",
      "cycle_id": "2025-02",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3550027",
      "title": "Assess and apply SAP security advisory 3550027",
      "source_title": "[CVE-2025-24869] Information Disclosure vulnerability in SAP NetWeaver Application Server Java | Product - SAP NetWeaver Application Server Java, Version - WD-RUNTIME 7.50",
      "source_url": "https://me.sap.com/notes/3550027",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "SAP NetWeaver Application Server Java, Version - WD-RUNTIME 7.50",
      "platform": "SAP",
      "release_version": "WD-RUNTIME 7.50",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 4.3",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 4.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-24869",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP NetWeaver Application Server Java, Version - WD-RUNTIME 7.50 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3550027 in its 2025-02 Security Patch Day release for SAP NetWeaver Application Server Java, Version - WD-RUNTIME 7.50. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-24869"
        ],
        "details": [
          {
            "id": "CVE-2025-24869",
            "title": "Information Disclosure vulnerability in SAP NetWeaver Application Server Java",
            "summary": "SAP NetWeaver Application Server Java allows an attacker to access an endpoint that can disclose information about deployed server components, including their XML definitions. This information should ideally be restricted to customer administrators, even though they may not need it. These XML files are not entirely SAP-internal as they are deployed with the server. In such a scenario, sensitive information could be e",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00255,
            "epssPercentile": 0.16943,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-02-3553753",
      "slug": "sap-2025-02-3553753",
      "cycle_id": "2025-02",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3553753",
      "title": "Assess and apply SAP security advisory 3553753",
      "source_title": "[CVE-2025-24872] Missing Authorization check in SAP ABAP Platform (ABAP Build Framework) | Product - SAP ABAP Platform (ABAP Build Framework), Versions - SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758",
      "source_url": "https://me.sap.com/notes/3553753",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "SAP ABAP Platform (ABAP Build Framework), Versions - SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758",
      "platform": "SAP",
      "release_version": "s - SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 4.3",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 4.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-24872",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP ABAP Platform (ABAP Build Framework), Versions - SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3553753 in its 2025-02 Security Patch Day release for SAP ABAP Platform (ABAP Build Framework), Versions - SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-24872"
        ],
        "details": [
          {
            "id": "CVE-2025-24872",
            "title": "Missing Authorization check in SAP ABAP Platform (ABAP Build Framework)",
            "summary": "The ABAP Build Framework in SAP ABAP Platform allows an authenticated attacker to gain unauthorized access to a specific transaction. By executing the add-on build functionality within the ABAP Build Framework, an attacker could call the transaction and view its details. This has a limited impact on the confidentiality of the application with no effect on the integrity and availability of the application.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00259,
            "epssPercentile": 0.17468,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-02-3555364",
      "slug": "sap-2025-02-3555364",
      "cycle_id": "2025-02",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3555364",
      "title": "Assess and apply SAP security advisory 3555364",
      "source_title": "[CVE-2025-24875] SameSite Defense in Depth not applied for some cookies in SAP Commerce Product- SAP Commerce, Versions – HY_COM 2205, COM_CLOUD 2211",
      "source_url": "https://me.sap.com/notes/3555364",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "SAP Commerce, Versions – HY_COM 2205, COM_CLOUD 2211",
      "platform": "SAP",
      "release_version": "s – HY_COM 2205, COM_CLOUD 2211",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 6.8",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 6.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-24875",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP Commerce, Versions – HY_COM 2205, COM_CLOUD 2211 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3555364 in its 2025-02 Security Patch Day release for SAP Commerce, Versions – HY_COM 2205, COM_CLOUD 2211. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-24875"
        ],
        "details": [
          {
            "id": "CVE-2025-24875",
            "title": "SameSite Defense in Depth not applied for some cookies in SAP Commerce",
            "summary": "SAP Commerce, by default, sets certain cookies with the SameSite attribute configured to None (SameSite=None). This includes authentication cookies utilized in SAP Commerce Backoffice. Applying this setting reduces defense in depth against CSRF and may lead to future compatibility issues.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00175,
            "epssPercentile": 0.07121,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-02-3557138",
      "slug": "sap-2025-02-3557138",
      "cycle_id": "2025-02",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3557138",
      "title": "Assess and apply SAP security advisory 3557138",
      "source_title": "Update 1 to Security Note 3417627 - [CVE-2024-22126] Cross Site Scripting vulnerability in NetWeaver AS Java (User Admin Application) Product- SAP NetWeaver AS Java (User Admin Application), Version – 7.50",
      "source_url": "https://me.sap.com/notes/3557138",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "SAP NetWeaver AS Java (User Admin Application), Version – 7.50",
      "platform": "SAP",
      "release_version": "7.50",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 6.1",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 6.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2024-22126",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP NetWeaver AS Java (User Admin Application), Version – 7.50 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3557138 in its 2025-02 Security Patch Day release for SAP NetWeaver AS Java (User Admin Application), Version – 7.50. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2024-22126"
        ],
        "details": [
          {
            "id": "CVE-2024-22126",
            "title": "Cross Site Scripting vulnerability in SAP NetWeaver AS Java (User Admin Application)",
            "summary": "The User Admin application of SAP NetWeaver AS for Java - version 7.50, insufficiently validates and improperly encodes the incoming URL parameters before including them into the redirect URL. This results in Cross-Site Scripting (XSS) vulnerability, leading to a high impact on confidentiality and mild impact on integrity and availability.",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00519,
            "epssPercentile": 0.42244,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-02-3559510",
      "slug": "sap-2025-02-3559510",
      "cycle_id": "2025-02",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3559510",
      "title": "Assess and apply SAP security advisory 3559510",
      "source_title": "[CVE-2025-24874] Missing Defense in Depth Against Clickjacking in SAP Commerce (Backoffice) Product – SAP Commerce (Backoffice), Version – HY_COM 2205, COM_CLOUD 2211",
      "source_url": "https://me.sap.com/notes/3559510",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "SAP Commerce (Backoffice), Version – HY_COM 2205, COM_CLOUD 2211",
      "platform": "SAP",
      "release_version": "HY_COM 2205, COM_CLOUD 2211",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 6.8",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 6.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-24874",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP Commerce (Backoffice), Version – HY_COM 2205, COM_CLOUD 2211 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3559510 in its 2025-02 Security Patch Day release for SAP Commerce (Backoffice), Version – HY_COM 2205, COM_CLOUD 2211. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-24874"
        ],
        "details": [
          {
            "id": "CVE-2025-24874",
            "title": "Missing Defense in Depth Against Clickjacking in SAP Commerce Backoffice",
            "summary": "SAP Commerce (Backoffice) uses the deprecated X-FRAME-OPTIONS header to protect against clickjacking. While this protection remains effective now, it may not be the case in the future as browsers might discontinue support for this header in favor of the frame-ancestors CSP directive. Hence, clickjacking could become possible then, and lead to exposure and modification of sensitive information.",
            "score": 6.8,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00323,
            "epssPercentile": 0.24961,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-02-3561264",
      "slug": "sap-2025-02-3561264",
      "cycle_id": "2025-02",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3561264",
      "title": "Assess and apply SAP security advisory 3561264",
      "source_title": "[CVE-2025-23193] Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP | Product- SAP NetWeaver Server ABAP, Versions – SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758",
      "source_url": "https://me.sap.com/notes/3561264",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "SAP NetWeaver Server ABAP, Versions – SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758",
      "platform": "SAP",
      "release_version": "s – SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 5.3",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 5.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-23193",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP NetWeaver Server ABAP, Versions – SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3561264 in its 2025-02 Security Patch Day release for SAP NetWeaver Server ABAP, Versions – SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-23193"
        ],
        "details": [
          {
            "id": "CVE-2025-23193",
            "title": "Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP",
            "summary": "SAP NetWeaver Server ABAP allows an unauthenticated attacker to exploit a vulnerability that causes the server to respond differently based on the existence of a specified user, potentially revealing sensitive information. This issue does not enable data modification and has no impact on server availability.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00349,
            "epssPercentile": 0.2793,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-02-3562336",
      "slug": "sap-2025-02-3562336",
      "cycle_id": "2025-02",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3562336",
      "title": "Assess and apply SAP security advisory 3562336",
      "source_title": "[CVE-2025-24870] Insecure Key & Secret Management vulnerability in SAP GUI for Windows Product- SAP GUI for Windows, Version – BC-FES-GUI 8.00",
      "source_url": "https://me.sap.com/notes/3562336",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "SAP GUI for Windows, Version – BC-FES-GUI 8.00",
      "platform": "SAP",
      "release_version": "BC-FES-GUI 8.00",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 6.0",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 6,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-24870",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP GUI for Windows, Version – BC-FES-GUI 8.00 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3562336 in its 2025-02 Security Patch Day release for SAP GUI for Windows, Version – BC-FES-GUI 8.00. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-24870"
        ],
        "details": [
          {
            "id": "CVE-2025-24870",
            "title": "Insecure Key & Secret Management vulnerability in SAP GUI for Windows",
            "summary": "SAP GUI for Windows & RFC service credentials are incorrectly stored in the memory of the program allowing an unauthenticated attacker to access information within systems, resulting in privilege escalation. On successful exploitation, this could result in disclosure of highly sensitive information. This has no impact on integrity, and availability.",
            "score": 6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00165,
            "epssPercentile": 0.05975,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-02-3563929",
      "slug": "sap-2025-02-3563929",
      "cycle_id": "2025-02",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3563929",
      "title": "Assess and apply SAP security advisory 3563929",
      "source_title": "[CVE-2025-24868] Open Redirect Vulnerability in SAP HANA extended application services, advanced model (User Account and Authentication Services) | Product - SAP HANA extended application services, advanced model (User Account and Authentication Services), Version - SAP_EXTENDED_APP_SERVICES 1",
      "source_url": "https://me.sap.com/notes/3563929",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "SAP HANA extended application services, advanced model (User Account and Authentication Services), Version - SAP_EXTENDED_APP_SERVICES 1",
      "platform": "SAP",
      "release_version": "SAP_EXTENDED_APP_SERVICES 1",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "High; CVSS 7.1",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-24868",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP HANA extended application services, advanced model (User Account and Authentication Services), Version - SAP_EXTENDED_APP_SERVICES 1 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3563929 in its 2025-02 Security Patch Day release for SAP HANA extended application services, advanced model (User Account and Authentication Services), Version - SAP_EXTENDED_APP_SERVICES 1. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-24868"
        ],
        "details": [
          {
            "id": "CVE-2025-24868",
            "title": "Open Redirect Vulnerability in SAP HANA extended application services, advanced model (User Account and Authentication Services)",
            "summary": "The User Account and Authentication service (UAA) for SAP HANA extended application services, advanced model (SAP HANA XS advanced model) allows an unauthenticated attacker to craft a malicious link, that, when clicked by a victim, redirects the browser to a malicious site due to insufficient redirect URL validation. On successful exploitation attacker can cause limited impact on confidentiality, integrity, and avail",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00249,
            "epssPercentile": 0.16123,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-02-3567172",
      "slug": "sap-2025-02-3567172",
      "cycle_id": "2025-02",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3567172",
      "title": "Assess and apply SAP security advisory 3567172",
      "source_title": "[CVE-2024-38819] Multiple vulnerabilities in SAP Enterprise Project Connection Related CVEs - CVE-2024-38820, CVE-2024-38828 | Product - SAP Enterprise Project Connection, Version – 3.0",
      "source_url": "https://me.sap.com/notes/3567172",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "SAP Enterprise Project Connection, Version – 3.0",
      "platform": "SAP",
      "release_version": "3.0",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "High; CVSS 7.5",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.5,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2024-38819",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP Enterprise Project Connection, Version – 3.0 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3567172 in its 2025-02 Security Patch Day release for SAP Enterprise Project Connection, Version – 3.0. The public bulletin links 3 CVEs; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 3,
        "ids": [
          "CVE-2024-38819",
          "CVE-2024-38820",
          "CVE-2024-38828"
        ],
        "details": [
          {
            "id": "CVE-2024-38819",
            "title": "Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks",
            "summary": "Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.54862,
            "epssPercentile": 0.98954,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2024-38820",
            "title": "CVE-2024-38820: Spring Framework DataBinder Case Sensitive Match Exception",
            "summary": "The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected.",
            "score": 3.1,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00617,
            "epssPercentile": 0.47362,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2024-38828",
            "title": "CVE-2024-38828: DoS via Spring MVC controller method with byte[] parameter",
            "summary": "Spring MVC controller methods with an @RequestBody byte[] method parameter are vulnerable to a DoS attack.",
            "score": 5.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00724,
            "epssPercentile": 0.51712,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-02-3567551",
      "slug": "sap-2025-02-3567551",
      "cycle_id": "2025-02",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3567551",
      "title": "Assess and apply SAP security advisory 3567551",
      "source_title": "[CVE-2025-25243] Path traversal vulnerability in SAP Supplier Relationship Management (Master Data Management Catalog) | Product - SAP Supplier Relationship Management (Master Data Management Catalog), Version - SRM_MDM_CAT 7.52",
      "source_url": "https://me.sap.com/notes/3567551",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "SAP Supplier Relationship Management (Master Data Management Catalog), Version - SRM_MDM_CAT 7.52",
      "platform": "SAP",
      "release_version": "SRM_MDM_CAT 7.52",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "High; CVSS 8.6",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.6,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-25243",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP Supplier Relationship Management (Master Data Management Catalog), Version - SRM_MDM_CAT 7.52 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3567551 in its 2025-02 Security Patch Day release for SAP Supplier Relationship Management (Master Data Management Catalog), Version - SRM_MDM_CAT 7.52. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-25243"
        ],
        "details": [
          {
            "id": "CVE-2025-25243",
            "title": "Path traversal vulnerability in SAP Supplier Relationship Management (Master Data Management Catalog)",
            "summary": "SAP Supplier Relationship Management (Master Data Management Catalog) allows an unauthenticated attacker to use a publicly available servlet to download an arbitrary file over the network without any user interaction. This can reveal highly sensitive information with no impact to integrity or availability.",
            "score": 8.6,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00697,
            "epssPercentile": 0.5073,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-02-3567974",
      "slug": "sap-2025-02-3567974",
      "cycle_id": "2025-02",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3567974",
      "title": "Assess and apply SAP security advisory 3567974",
      "source_title": "[CVE-2025-24876] Authentication bypass via authorization code injection in SAP Approuter | Library - @sap/approuter, Version - 2.6.1 to 16.7.1",
      "source_url": "https://me.sap.com/notes/3567974",
      "published_at": "2025-02-11",
      "updated_at": "2025-02-11",
      "status": "active",
      "product": "SAP product listed in the Patch Day bulletin",
      "platform": "SAP",
      "release_version": "2.6.1 to 16.7.1",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "High; CVSS 8.1",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-24876",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP product listed in the Patch Day bulletin exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3567974 in its 2025-02 Security Patch Day release for SAP product listed in the Patch Day bulletin. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-24876"
        ],
        "details": [
          {
            "id": "CVE-2025-24876",
            "title": "Authentication bypass via authorization code injection in SAP Approuter",
            "summary": "The SAP Approuter Node.js package version v16.7.1 and before is vulnerable to Authentication bypass. When trading an authorization code an attacker can steal the session of the victim by injecting malicious payload causing High impact on confidentiality and integrity of the application",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00495,
            "epssPercentile": 0.40739,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-02-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "adobe-apsb25-16",
      "slug": "adobe-apsb25-16",
      "cycle_id": "2025-03",
      "vendor_id": "adobe",
      "vendor_name": "Adobe",
      "source_id": "adobe-security-bulletins",
      "advisory_id": "APSB25-16",
      "title": "Update Adobe Substance 3D Sampler to the fixed Adobe release",
      "source_title": "APSB25-16 : Security update available for Adobe Substance 3D Sampler",
      "source_url": "https://helpx.adobe.com/security/products/substance3d-sampler/apsb25-16.html",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Adobe Substance 3D Sampler",
      "platform": "All",
      "release_version": "5.0",
      "action_type": "upgrade-release",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 7.8; Adobe priority 3",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-24445",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Adobe Substance 3D Sampler exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "Adobe published APSB25-16 on Patch Tuesday for Adobe Substance 3D Sampler. The bulletin links 7 CVEs and provides fixed release guidance.",
      "cves": {
        "state": "complete-for-advisory",
        "vendor_stated_count": 7,
        "ids": [
          "CVE-2025-24439",
          "CVE-2025-24440",
          "CVE-2025-24441",
          "CVE-2025-24442",
          "CVE-2025-24443",
          "CVE-2025-24444",
          "CVE-2025-24445"
        ],
        "details": [
          {
            "id": "CVE-2025-24439",
            "title": "Substance3D - Sampler | Heap-based Buffer Overflow (CWE-122)",
            "summary": "Substance3D - Sampler versions 4.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00295,
            "epssPercentile": 0.21747,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24440",
            "title": "Substance3D - Sampler | Out-of-bounds Write (CWE-787)",
            "summary": "Substance3D - Sampler versions 4.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00242,
            "epssPercentile": 0.15263,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24441",
            "title": "Substance3D - Sampler | Out-of-bounds Write (CWE-787)",
            "summary": "Substance3D - Sampler versions 4.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00228,
            "epssPercentile": 0.13461,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24442",
            "title": "Substance3D - Sampler | Out-of-bounds Write (CWE-787)",
            "summary": "Substance3D - Sampler versions 4.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00228,
            "epssPercentile": 0.1346,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24443",
            "title": "Substance3D - Sampler | Heap-based Buffer Overflow (CWE-122)",
            "summary": "Substance3D - Sampler versions 4.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00278,
            "epssPercentile": 0.1994,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24444",
            "title": "Substance3D - Sampler | Out-of-bounds Write (CWE-787)",
            "summary": "Substance3D - Sampler versions 4.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00228,
            "epssPercentile": 0.13461,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24445",
            "title": "Substance3D - Sampler | Out-of-bounds Write (CWE-787)",
            "summary": "Substance3D - Sampler versions 4.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00228,
            "epssPercentile": 0.13461,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update path and test the fixed release against managed plug-ins, workflows and file formats before broad deployment."
      ],
      "data_gaps": [
        "Restart requirements are not asserted unless the reviewed bulletin states them explicitly."
      ],
      "provenance": [
        {
          "field": "advisory_identity_and_release",
          "source_path": "adobe-bulletin/solution",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships",
          "source_path": "adobe-bulletin/vulnerability-details",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial publication of APSB25-16."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The bulletin identity, release date, fixed versions, platforms, vendor signals and complete public CVE list were generated from the official Adobe bulletin and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "adobe-apsb25-18",
      "slug": "adobe-apsb25-18",
      "cycle_id": "2025-03",
      "vendor_id": "adobe",
      "vendor_name": "Adobe",
      "source_id": "adobe-security-bulletins",
      "advisory_id": "APSB25-18",
      "title": "Update Adobe Substance 3D Painter to the fixed Adobe release",
      "source_title": "APSB25-18 : Security update available for Adobe Substance 3D Painter",
      "source_url": "https://helpx.adobe.com/security/products/substance3d_painter/apsb25-18.html",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Adobe Substance 3D Painter",
      "platform": "All",
      "release_version": "11.0",
      "action_type": "upgrade-release",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 7.8; Adobe priority 3",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-24451",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Adobe Substance 3D Painter exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "Adobe published APSB25-18 on Patch Tuesday for Adobe Substance 3D Painter. The bulletin links 2 CVEs and provides fixed release guidance.",
      "cves": {
        "state": "complete-for-advisory",
        "vendor_stated_count": 2,
        "ids": [
          "CVE-2025-24450",
          "CVE-2025-24451"
        ],
        "details": [
          {
            "id": "CVE-2025-24450",
            "title": "Substance3D - Painter | Out-of-bounds Write (CWE-787)",
            "summary": "Substance3D - Painter versions 10.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00242,
            "epssPercentile": 0.15263,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24451",
            "title": "Substance3D - Painter | Out-of-bounds Write (CWE-787)",
            "summary": "Substance3D - Painter versions 10.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00242,
            "epssPercentile": 0.15263,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update path and test the fixed release against managed plug-ins, workflows and file formats before broad deployment."
      ],
      "data_gaps": [
        "Restart requirements are not asserted unless the reviewed bulletin states them explicitly."
      ],
      "provenance": [
        {
          "field": "advisory_identity_and_release",
          "source_path": "adobe-bulletin/solution",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships",
          "source_path": "adobe-bulletin/vulnerability-details",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial publication of APSB25-18."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The bulletin identity, release date, fixed versions, platforms, vendor signals and complete public CVE list were generated from the official Adobe bulletin and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "adobe-apsb25-21",
      "slug": "adobe-apsb25-21",
      "cycle_id": "2025-03",
      "vendor_id": "adobe",
      "vendor_name": "Adobe",
      "source_id": "adobe-security-bulletins",
      "advisory_id": "APSB25-21",
      "title": "Update Adobe Substance 3D Modeler to the fixed Adobe release",
      "source_title": "APSB25-21 : Security update available for Adobe Substance 3D Modeler",
      "source_url": "https://helpx.adobe.com/security/products/substance3d-modeler/apsb25-21.html",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Adobe Substance 3D Modeler",
      "platform": "All",
      "release_version": "1.21.0",
      "action_type": "upgrade-release",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 7.8; Adobe priority 3",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-27181",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Adobe Substance 3D Modeler exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "Adobe published APSB25-21 on Patch Tuesday for Adobe Substance 3D Modeler. The bulletin links 4 CVEs and provides fixed release guidance.",
      "cves": {
        "state": "complete-for-advisory",
        "vendor_stated_count": 4,
        "ids": [
          "CVE-2025-21170",
          "CVE-2025-27173",
          "CVE-2025-27180",
          "CVE-2025-27181"
        ],
        "details": [
          {
            "id": "CVE-2025-21170",
            "title": "Substance3D - Modeler | NULL Pointer Dereference (CWE-476)",
            "summary": "Substance3D - Modeler versions 1.15.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00218,
            "epssPercentile": 0.12225,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-27173",
            "title": "Substance3D - Modeler | Heap-based Buffer Overflow (CWE-122)",
            "summary": "Substance3D - Modeler versions 1.15.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00295,
            "epssPercentile": 0.21746,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-27180",
            "title": "Substance3D - Modeler | Out-of-bounds Read (CWE-125)",
            "summary": "Substance3D - Modeler versions 1.15.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15732,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-27181",
            "title": "Substance3D - Modeler | Use After Free (CWE-416)",
            "summary": "Substance3D - Modeler versions 1.15.0 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00294,
            "epssPercentile": 0.21639,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update path and test the fixed release against managed plug-ins, workflows and file formats before broad deployment."
      ],
      "data_gaps": [
        "Restart requirements are not asserted unless the reviewed bulletin states them explicitly."
      ],
      "provenance": [
        {
          "field": "advisory_identity_and_release",
          "source_path": "adobe-bulletin/solution",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships",
          "source_path": "adobe-bulletin/vulnerability-details",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial publication of APSB25-21."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The bulletin identity, release date, fixed versions, platforms, vendor signals and complete public CVE list were generated from the official Adobe bulletin and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "adobe-apsb25-22",
      "slug": "adobe-apsb25-22",
      "cycle_id": "2025-03",
      "vendor_id": "adobe",
      "vendor_name": "Adobe",
      "source_id": "adobe-security-bulletins",
      "advisory_id": "APSB25-22",
      "title": "Update Adobe Substance 3D Designer to the fixed Adobe release",
      "source_title": "APSB25-22 : Security update available for Adobe Substance 3D Designer",
      "source_url": "https://helpx.adobe.com/security/products/substance3d_designer/apsb25-22.html",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Adobe Substance 3D Designer",
      "platform": "All",
      "release_version": "14.1.1",
      "action_type": "upgrade-release",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 7.8; Adobe priority 3",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-27172",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Adobe Substance 3D Designer exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "Adobe published APSB25-22 on Patch Tuesday for Adobe Substance 3D Designer. The bulletin links 2 CVEs and provides fixed release guidance.",
      "cves": {
        "state": "complete-for-advisory",
        "vendor_stated_count": 2,
        "ids": [
          "CVE-2025-21169",
          "CVE-2025-27172"
        ],
        "details": [
          {
            "id": "CVE-2025-21169",
            "title": "Substance3D - Designer | Heap-based Buffer Overflow (CWE-122)",
            "summary": "Substance3D - Designer versions 14.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00295,
            "epssPercentile": 0.21746,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-27172",
            "title": "Substance3D - Designer | Out-of-bounds Write (CWE-787)",
            "summary": "Substance3D - Designer versions 14.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00225,
            "epssPercentile": 0.13135,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update path and test the fixed release against managed plug-ins, workflows and file formats before broad deployment."
      ],
      "data_gaps": [
        "Restart requirements are not asserted unless the reviewed bulletin states them explicitly."
      ],
      "provenance": [
        {
          "field": "advisory_identity_and_release",
          "source_path": "adobe-bulletin/solution",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships",
          "source_path": "adobe-bulletin/vulnerability-details",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial publication of APSB25-22."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The bulletin identity, release date, fixed versions, platforms, vendor signals and complete public CVE list were generated from the official Adobe bulletin and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "adobe-apsb25-14",
      "slug": "adobe-apsb25-14",
      "cycle_id": "2025-03",
      "vendor_id": "adobe",
      "vendor_name": "Adobe",
      "source_id": "adobe-security-bulletins",
      "advisory_id": "APSB25-14",
      "title": "Update Adobe Acrobat Reader to the fixed Adobe release",
      "source_title": "APSB25-14 : Security update available for Adobe Acrobat Reader",
      "source_url": "https://helpx.adobe.com/security/products/acrobat/apsb25-14.html",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Adobe Acrobat Reader",
      "platform": "See Adobe bulletin",
      "release_version": null,
      "action_type": "upgrade-release",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 7.8",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-27174",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Adobe Acrobat Reader exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "Adobe published APSB25-14 on Patch Tuesday for Adobe Acrobat Reader. The bulletin links 9 CVEs and provides fixed release guidance.",
      "cves": {
        "state": "complete-for-advisory",
        "vendor_stated_count": 9,
        "ids": [
          "CVE-2025-24431",
          "CVE-2025-27158",
          "CVE-2025-27159",
          "CVE-2025-27160",
          "CVE-2025-27161",
          "CVE-2025-27162",
          "CVE-2025-27163",
          "CVE-2025-27164",
          "CVE-2025-27174"
        ],
        "details": [
          {
            "id": "CVE-2025-24431",
            "title": "Acrobat Reader | Out-of-bounds Read (CWE-125)",
            "summary": "Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00432,
            "epssPercentile": 0.36201,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-27158",
            "title": "Acrobat Reader | Access of Uninitialized Pointer (CWE-824)",
            "summary": "Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00447,
            "epssPercentile": 0.37506,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-27159",
            "title": "Acrobat Reader | Use After Free (CWE-416)",
            "summary": "Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00353,
            "epssPercentile": 0.28323,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-27160",
            "title": "Acrobat Reader | Use After Free (CWE-416)",
            "summary": "Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00353,
            "epssPercentile": 0.28323,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-27161",
            "title": "Acrobat Reader | Out-of-bounds Read (CWE-125)",
            "summary": "Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malici",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00325,
            "epssPercentile": 0.25181,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-27162",
            "title": "Acrobat Reader | Access of Uninitialized Pointer (CWE-824)",
            "summary": "Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00322,
            "epssPercentile": 0.24784,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-27163",
            "title": "Acrobat Reader | Out-of-bounds Read (CWE-125)",
            "summary": "Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00417,
            "epssPercentile": 0.34942,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-27164",
            "title": "Acrobat Reader | Out-of-bounds Read (CWE-125)",
            "summary": "Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00412,
            "epssPercentile": 0.34473,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-27174",
            "title": "Acrobat Reader | Use After Free (CWE-416)",
            "summary": "Acrobat Reader versions 24.001.30225, 20.005.30748, 25.001.20428 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00353,
            "epssPercentile": 0.28323,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update path and test the fixed release against managed plug-ins, workflows and file formats before broad deployment."
      ],
      "data_gaps": [
        "Restart requirements are not asserted unless the reviewed bulletin states them explicitly."
      ],
      "provenance": [
        {
          "field": "advisory_identity_and_release",
          "source_path": "adobe-bulletin/solution",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships",
          "source_path": "adobe-bulletin/vulnerability-details",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial publication of APSB25-14."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The bulletin identity, release date, fixed versions, platforms, vendor signals and complete public CVE list were generated from the official Adobe bulletin and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "adobe-apsb25-17",
      "slug": "adobe-apsb25-17",
      "cycle_id": "2025-03",
      "vendor_id": "adobe",
      "vendor_name": "Adobe",
      "source_id": "adobe-security-bulletins",
      "advisory_id": "APSB25-17",
      "title": "Update Adobe Illustrator to the fixed Adobe release",
      "source_title": "APSB25-17 : Security update available for Adobe Illustrator",
      "source_url": "https://helpx.adobe.com/security/products/illustrator/apsb25-17.html",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Adobe Illustrator",
      "platform": "Windows and macOS",
      "release_version": "29.3 and above, 28.7.5 and above",
      "action_type": "upgrade-release",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 7.8; Adobe priority 3",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-27169",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Adobe Illustrator exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "Adobe published APSB25-17 on Patch Tuesday for Adobe Illustrator. The bulletin links 6 CVEs and provides fixed release guidance.",
      "cves": {
        "state": "complete-for-advisory",
        "vendor_stated_count": 6,
        "ids": [
          "CVE-2025-24448",
          "CVE-2025-24449",
          "CVE-2025-27167",
          "CVE-2025-27168",
          "CVE-2025-27169",
          "CVE-2025-27170"
        ],
        "details": [
          {
            "id": "CVE-2025-24448",
            "title": "Illustrator | Out-of-bounds Read (CWE-125)",
            "summary": "Illustrator versions 29.2.1, 28.7.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00231,
            "epssPercentile": 0.1391,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24449",
            "title": "Illustrator | Out-of-bounds Read (CWE-125)",
            "summary": "Illustrator versions 29.2.1, 28.7.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00246,
            "epssPercentile": 0.15732,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-27167",
            "title": "Illustrator | Untrusted Search Path (CWE-426)",
            "summary": "Illustrator versions 29.2.1, 28.7.4 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute their own programs, access unauthorized data files, or modify configuration in unexpected ways. If the application uses a search path to locate critical resources such as programs, then an attacker could modify that search path to point to a malicious program, which the targeted",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00228,
            "epssPercentile": 0.13489,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-27168",
            "title": "Illustrator | Stack-based Buffer Overflow (CWE-121)",
            "summary": "Illustrator versions 29.2.1, 28.7.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00275,
            "epssPercentile": 0.1956,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-27169",
            "title": "Illustrator | Out-of-bounds Write (CWE-787)",
            "summary": "Illustrator versions 29.2.1, 28.7.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00225,
            "epssPercentile": 0.13135,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-27170",
            "title": "Illustrator | NULL Pointer Dereference (CWE-476)",
            "summary": "Illustrator versions 29.2.1, 28.7.4 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial of service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00198,
            "epssPercentile": 0.09695,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update path and test the fixed release against managed plug-ins, workflows and file formats before broad deployment."
      ],
      "data_gaps": [
        "Restart requirements are not asserted unless the reviewed bulletin states them explicitly."
      ],
      "provenance": [
        {
          "field": "advisory_identity_and_release",
          "source_path": "adobe-bulletin/solution",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships",
          "source_path": "adobe-bulletin/vulnerability-details",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial publication of APSB25-17."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The bulletin identity, release date, fixed versions, platforms, vendor signals and complete public CVE list were generated from the official Adobe bulletin and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "adobe-apsb25-19",
      "slug": "adobe-apsb25-19",
      "cycle_id": "2025-03",
      "vendor_id": "adobe",
      "vendor_name": "Adobe",
      "source_id": "adobe-security-bulletins",
      "advisory_id": "APSB25-19",
      "title": "Update Adobe InDesign to the fixed Adobe release",
      "source_title": "APSB25-19 : Security update available for Adobe InDesign",
      "source_url": "https://helpx.adobe.com/security/products/indesign/apsb25-19.html",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Adobe InDesign",
      "platform": "Windows and macOS",
      "release_version": "ID20.2, ID19.5.3",
      "action_type": "upgrade-release",
      "restart_required": "unknown",
      "vendor_severity": "Critical; CVSS 7.8; Adobe priority 3",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-27178",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Adobe InDesign exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "Adobe published APSB25-19 on Patch Tuesday for Adobe InDesign. The bulletin links 9 CVEs and provides fixed release guidance.",
      "cves": {
        "state": "complete-for-advisory",
        "vendor_stated_count": 9,
        "ids": [
          "CVE-2025-24452",
          "CVE-2025-24453",
          "CVE-2025-27166",
          "CVE-2025-27171",
          "CVE-2025-27175",
          "CVE-2025-27176",
          "CVE-2025-27177",
          "CVE-2025-27178",
          "CVE-2025-27179"
        ],
        "details": [
          {
            "id": "CVE-2025-24452",
            "title": "InDesign Desktop | Out-of-bounds Write (CWE-787)",
            "summary": "InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00284,
            "epssPercentile": 0.20608,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24453",
            "title": "InDesign Desktop | Heap-based Buffer Overflow (CWE-122)",
            "summary": "InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00322,
            "epssPercentile": 0.24866,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-27166",
            "title": "InDesign Desktop | Out-of-bounds Write (CWE-787)",
            "summary": "InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18173,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-27171",
            "title": "InDesign Desktop | Heap-based Buffer Overflow (CWE-122)",
            "summary": "InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00322,
            "epssPercentile": 0.24866,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-27175",
            "title": "InDesign Desktop | Out-of-bounds Write (CWE-787)",
            "summary": "InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00264,
            "epssPercentile": 0.18173,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-27176",
            "title": "InDesign Desktop | NULL Pointer Dereference (CWE-476)",
            "summary": "InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00239,
            "epssPercentile": 0.14837,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-27177",
            "title": "InDesign Desktop | Heap-based Buffer Overflow (CWE-122)",
            "summary": "InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00322,
            "epssPercentile": 0.24867,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-27178",
            "title": "InDesign Desktop | Out-of-bounds Write (CWE-787)",
            "summary": "InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00263,
            "epssPercentile": 0.17931,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-27179",
            "title": "InDesign Desktop | NULL Pointer Dereference (CWE-476)",
            "summary": "InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00239,
            "epssPercentile": 0.14838,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update path and test the fixed release against managed plug-ins, workflows and file formats before broad deployment."
      ],
      "data_gaps": [
        "Restart requirements are not asserted unless the reviewed bulletin states them explicitly."
      ],
      "provenance": [
        {
          "field": "advisory_identity_and_release",
          "source_path": "adobe-bulletin/solution",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships",
          "source_path": "adobe-bulletin/vulnerability-details",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial publication of APSB25-19."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The bulletin identity, release date, fixed versions, platforms, vendor signals and complete public CVE list were generated from the official Adobe bulletin and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-azure-msrc-2025-03-azure-release-notes-azure-promptflow-core",
      "slug": "microsoft-2025-03-azure-msrc-2025-03-azure-release-notes-azure-promptflow-core",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-03-azure-release-notes",
      "title": "Deploy Microsoft Azure update for Azure promptflow-core",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://pypi.org/project/promptflow-core/1.17.2/",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Azure promptflow-core",
      "platform": "Azure",
      "release_version": "1.17.2",
      "action_type": "deploy-patch",
      "restart_required": "no",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 6.5,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-24986",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "The reviewed source does not require a restart.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Azure promptflow-core exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure promptflow-core.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-24986"
        ],
        "details": [
          {
            "id": "CVE-2025-24986",
            "title": "Azure Promptflow Remote Code Execution Vulnerability",
            "summary": "Improper isolation or compartmentalization in Azure PromptFlow allows an unauthorized attacker to execute code over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00519,
            "epssPercentile": 0.42252,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-azure-msrc-2025-03-azure-release-notes-azure-promptflow-tools",
      "slug": "microsoft-2025-03-azure-msrc-2025-03-azure-release-notes-azure-promptflow-tools",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-03-azure-release-notes",
      "title": "Deploy Microsoft Azure update for Azure promptflow-tools",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://pypi.org/project/promptflow-tools/1.6.0/",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Azure promptflow-tools",
      "platform": "Azure",
      "release_version": "1.6.0",
      "action_type": "deploy-patch",
      "restart_required": "no",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 6.5,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-24986",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "The reviewed source does not require a restart.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Azure promptflow-tools exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure promptflow-tools.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-24986"
        ],
        "details": [
          {
            "id": "CVE-2025-24986",
            "title": "Azure Promptflow Remote Code Execution Vulnerability",
            "summary": "Improper isolation or compartmentalization in Azure PromptFlow allows an unauthorized attacker to execute code over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00519,
            "epssPercentile": 0.42252,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-azure-msrc-2025-03-azure-release-notes-azure-agent-for-site-recovery",
      "slug": "microsoft-2025-03-azure-msrc-2025-03-azure-release-notes-azure-agent-for-site-recovery",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-03-azure-release-notes",
      "title": "Deploy Microsoft Azure update for Azure Agent for Site Recovery",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/en-us/topic/update-rollup-76-for-azure-site-recovery-6ca6833a-5b0f-4bdf-9946-41cd0aa8d6e4",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Azure Agent for Site Recovery",
      "platform": "Azure",
      "release_version": "9.30",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 6.7,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21199",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Azure Agent for Site Recovery exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Agent for Site Recovery.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21199"
        ],
        "details": [
          {
            "id": "CVE-2025-21199",
            "title": "Azure Agent Installer for Backup and Site Recovery Elevation of Privilege Vulnerability",
            "summary": "Improper privilege management in Azure Agent Installer allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00437,
            "epssPercentile": 0.36713,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-azure-msrc-2025-03-azure-release-notes-azure-agent-for-backup",
      "slug": "microsoft-2025-03-azure-msrc-2025-03-azure-release-notes-azure-agent-for-backup",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-03-azure-release-notes",
      "title": "Deploy Microsoft Azure update for Azure Agent for Backup",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/en-us/topic/update-rollup-76-for-azure-site-recovery-6ca6833a-5b0f-4bdf-9946-41cd0aa8d6e4",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Azure Agent for Backup",
      "platform": "Azure",
      "release_version": "2.0.9940.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 6.7,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21199",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Azure Agent for Backup exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Agent for Backup.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21199"
        ],
        "details": [
          {
            "id": "CVE-2025-21199",
            "title": "Azure Agent Installer for Backup and Site Recovery Elevation of Privilege Vulnerability",
            "summary": "Improper privilege management in Azure Agent Installer allows an authorized attacker to elevate privileges locally.",
            "score": 6.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00437,
            "epssPercentile": 0.36713,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-azure-msrc-2025-03-azure-release-notes-azure-cli",
      "slug": "microsoft-2025-03-azure-msrc-2025-03-azure-release-notes-azure-cli",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-03-azure-release-notes",
      "title": "Deploy Microsoft Azure update for Azure CLI",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://learn.microsoft.com/en-us/cli/azure/install-azure-cli",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Azure CLI",
      "platform": "Azure",
      "release_version": "2.69.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.4,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-24049",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Azure CLI exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure CLI.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-24049"
        ],
        "details": [
          {
            "id": "CVE-2025-24049",
            "title": "Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability",
            "summary": "Improper neutralization of special elements used in a command ('command injection') in Azure Command Line Integration (CLI) allows an unauthorized attacker to elevate privileges locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00422,
            "epssPercentile": 0.35389,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-azure-msrc-2025-03-azure-what-s-new-azure-arc",
      "slug": "microsoft-2025-03-azure-msrc-2025-03-azure-what-s-new-azure-arc",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-03-azure-what-s-new",
      "title": "Deploy Microsoft Azure update for Azure ARC",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://docs.microsoft.com/en-us/azure/azure-arc/servers/agent-release-notes",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Azure ARC",
      "platform": "Azure",
      "release_version": "1.0.10",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-26627",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Azure ARC exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure ARC.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-26627"
        ],
        "details": [
          {
            "id": "CVE-2025-26627",
            "title": "Azure Arc Installer Elevation of Privilege Vulnerability",
            "summary": "Improper neutralization of special elements used in a command ('command injection') in Azure Arc allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00872,
            "epssPercentile": 0.5652,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-developer-tools-kb5054229",
      "slug": "microsoft-2025-03-developer-tools-kb5054229",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5054229",
      "title": "Deploy Microsoft Developer Tools security update KB5054229",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5054229",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "ASP.NET Core 8.0",
      "platform": "Developer Tools",
      "release_version": "8.0.14",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-24070",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is ASP.NET Core 8.0 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for ASP.NET Core 8.0.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-24070"
        ],
        "details": [
          {
            "id": "CVE-2025-24070",
            "title": "ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability",
            "summary": "Weak authentication in ASP.NET Core &amp; Visual Studio allows an unauthorized attacker to elevate privileges over a network.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.00968,
            "epssPercentile": 0.59553,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-developer-tools-kb5054230",
      "slug": "microsoft-2025-03-developer-tools-kb5054230",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5054230",
      "title": "Deploy Microsoft Developer Tools security update KB5054230",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5054230",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "ASP.NET Core 9.0",
      "platform": "Developer Tools",
      "release_version": "9.0.3",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-24070",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is ASP.NET Core 9.0 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for ASP.NET Core 9.0.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-24070"
        ],
        "details": [
          {
            "id": "CVE-2025-24070",
            "title": "ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability",
            "summary": "Weak authentication in ASP.NET Core &amp; Visual Studio allows an unauthorized attacker to elevate privileges over a network.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.00968,
            "epssPercentile": 0.59553,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-developer-tools-msrc-2025-03-developer-tools-release-notes-windbg",
      "slug": "microsoft-2025-03-developer-tools-msrc-2025-03-developer-tools-release-notes-windbg",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-03-developer-tools-release-notes",
      "title": "Deploy Microsoft Developer Tools update for WinDbg",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://apps.microsoft.com/detail/WinDbg Preview/9PGJGD53TN86?launch=true&mode=mini",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "WinDbg",
      "platform": "Developer Tools",
      "release_version": "1.2502.25002.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.5,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-24043",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is WinDbg exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for WinDbg.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-24043"
        ],
        "details": [
          {
            "id": "CVE-2025-24043",
            "title": "WinDbg Remote Code Execution Vulnerability",
            "summary": "Improper verification of cryptographic signature in .NET allows an authorized attacker to execute code over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00873,
            "epssPercentile": 0.56548,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-developer-tools-msrc-2025-03-developer-tools-release-notes-microsoft-visual-studio-2022-version-17-12",
      "slug": "microsoft-2025-03-developer-tools-msrc-2025-03-developer-tools-release-notes-microsoft-visual-studio-2022-version-17-12",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-03-developer-tools-release-notes",
      "title": "Deploy Microsoft Developer Tools update for Microsoft Visual Studio 2022 version 17.12",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.12",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Microsoft Visual Studio 2022 version 17.12",
      "platform": "Developer Tools",
      "release_version": "17.12.6",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-25003",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Visual Studio 2022 version 17.12 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft Visual Studio 2022 version 17.12.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 3,
        "ids": [
          "CVE-2025-24070",
          "CVE-2025-24998",
          "CVE-2025-25003"
        ],
        "details": [
          {
            "id": "CVE-2025-24070",
            "title": "ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability",
            "summary": "Weak authentication in ASP.NET Core &amp; Visual Studio allows an unauthorized attacker to elevate privileges over a network.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.00968,
            "epssPercentile": 0.59553,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24998",
            "title": "Visual Studio Elevation of Privilege Vulnerability",
            "summary": "Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00447,
            "epssPercentile": 0.37485,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-25003",
            "title": "Visual Studio Elevation of Privilege Vulnerability",
            "summary": "Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00447,
            "epssPercentile": 0.37485,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-developer-tools-msrc-2025-03-developer-tools-release-notes-microsoft-visual-studio-2022-version-17-13",
      "slug": "microsoft-2025-03-developer-tools-msrc-2025-03-developer-tools-release-notes-microsoft-visual-studio-2022-version-17-13",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-03-developer-tools-release-notes",
      "title": "Deploy Microsoft Developer Tools update for Microsoft Visual Studio 2022 version 17.13",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.13",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Microsoft Visual Studio 2022 version 17.13",
      "platform": "Developer Tools",
      "release_version": "17.13.3",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-25003",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Visual Studio 2022 version 17.13 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft Visual Studio 2022 version 17.13.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 3,
        "ids": [
          "CVE-2025-24070",
          "CVE-2025-24998",
          "CVE-2025-25003"
        ],
        "details": [
          {
            "id": "CVE-2025-24070",
            "title": "ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability",
            "summary": "Weak authentication in ASP.NET Core &amp; Visual Studio allows an unauthorized attacker to elevate privileges over a network.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.00968,
            "epssPercentile": 0.59553,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24998",
            "title": "Visual Studio Elevation of Privilege Vulnerability",
            "summary": "Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00447,
            "epssPercentile": 0.37485,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-25003",
            "title": "Visual Studio Elevation of Privilege Vulnerability",
            "summary": "Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00447,
            "epssPercentile": 0.37485,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-developer-tools-msrc-2025-03-developer-tools-release-notes-microsoft-visual-studio-2022-version-17-8",
      "slug": "microsoft-2025-03-developer-tools-msrc-2025-03-developer-tools-release-notes-microsoft-visual-studio-2022-version-17-8",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-03-developer-tools-release-notes",
      "title": "Deploy Microsoft Developer Tools update for Microsoft Visual Studio 2022 version 17.8",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.8",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Microsoft Visual Studio 2022 version 17.8",
      "platform": "Developer Tools",
      "release_version": "17.8.19",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-25003",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Visual Studio 2022 version 17.8 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft Visual Studio 2022 version 17.8.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 3,
        "ids": [
          "CVE-2025-24070",
          "CVE-2025-24998",
          "CVE-2025-25003"
        ],
        "details": [
          {
            "id": "CVE-2025-24070",
            "title": "ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability",
            "summary": "Weak authentication in ASP.NET Core &amp; Visual Studio allows an unauthorized attacker to elevate privileges over a network.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.00968,
            "epssPercentile": 0.59553,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24998",
            "title": "Visual Studio Elevation of Privilege Vulnerability",
            "summary": "Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00447,
            "epssPercentile": 0.37485,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-25003",
            "title": "Visual Studio Elevation of Privilege Vulnerability",
            "summary": "Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00447,
            "epssPercentile": 0.37485,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-developer-tools-msrc-2025-03-developer-tools-release-notes-microsoft-visual-studio-2022-version-17-10",
      "slug": "microsoft-2025-03-developer-tools-msrc-2025-03-developer-tools-release-notes-microsoft-visual-studio-2022-version-17-10",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-03-developer-tools-release-notes",
      "title": "Deploy Microsoft Developer Tools update for Microsoft Visual Studio 2022 version 17.10",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.10",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Microsoft Visual Studio 2022 version 17.10",
      "platform": "Developer Tools",
      "release_version": "17.10.12",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-25003",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Visual Studio 2022 version 17.10 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft Visual Studio 2022 version 17.10.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 3,
        "ids": [
          "CVE-2025-24070",
          "CVE-2025-24998",
          "CVE-2025-25003"
        ],
        "details": [
          {
            "id": "CVE-2025-24070",
            "title": "ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability",
            "summary": "Weak authentication in ASP.NET Core &amp; Visual Studio allows an unauthorized attacker to elevate privileges over a network.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.00968,
            "epssPercentile": 0.59553,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24998",
            "title": "Visual Studio Elevation of Privilege Vulnerability",
            "summary": "Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00447,
            "epssPercentile": 0.37485,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-25003",
            "title": "Visual Studio Elevation of Privilege Vulnerability",
            "summary": "Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00447,
            "epssPercentile": 0.37485,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-developer-tools-msrc-2025-03-developer-tools-release-notes-microsoft-visual-studio-2017-version-15-9-includes-15-0-15-8",
      "slug": "microsoft-2025-03-developer-tools-msrc-2025-03-developer-tools-release-notes-microsoft-visual-studio-2017-version-15-9-includes-15-0-15-8",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-03-developer-tools-release-notes",
      "title": "Deploy Microsoft Developer Tools update for Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://aka.ms/vs/15/release/latest",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)",
      "platform": "Developer Tools",
      "release_version": "15.9.71",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-24998",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-24998"
        ],
        "details": [
          {
            "id": "CVE-2025-24998",
            "title": "Visual Studio Elevation of Privilege Vulnerability",
            "summary": "Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00447,
            "epssPercentile": 0.37485,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-developer-tools-msrc-2025-03-developer-tools-release-notes-microsoft-visual-studio-2019-version-16-11-includes-16-0-16-10",
      "slug": "microsoft-2025-03-developer-tools-msrc-2025-03-developer-tools-release-notes-microsoft-visual-studio-2019-version-16-11-includes-16-0-16-10",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-03-developer-tools-release-notes",
      "title": "Deploy Microsoft Developer Tools update for Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://my.visualstudio.com/Downloads?q=Visual Studio 2019 version 16.11",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)",
      "platform": "Developer Tools",
      "release_version": "16.11.45",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-25003",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 2,
        "ids": [
          "CVE-2025-24998",
          "CVE-2025-25003"
        ],
        "details": [
          {
            "id": "CVE-2025-24998",
            "title": "Visual Studio Elevation of Privilege Vulnerability",
            "summary": "Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00447,
            "epssPercentile": 0.37485,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-25003",
            "title": "Visual Studio Elevation of Privilege Vulnerability",
            "summary": "Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00447,
            "epssPercentile": 0.37485,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-developer-tools-msrc-2025-03-developer-tools-release-notes-visual-studio-code",
      "slug": "microsoft-2025-03-developer-tools-msrc-2025-03-developer-tools-release-notes-visual-studio-code",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-03-developer-tools-release-notes",
      "title": "Deploy Microsoft Developer Tools update for Visual Studio Code",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://code.visualstudio.com/download",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Visual Studio Code",
      "platform": "Developer Tools",
      "release_version": "1.98.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-26631",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Visual Studio Code exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Visual Studio Code.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-26631"
        ],
        "details": [
          {
            "id": "CVE-2025-26631",
            "title": "Visual Studio Code Elevation of Privilege Vulnerability",
            "summary": "Uncontrolled search path element in Visual Studio Code allows an authorized attacker to elevate privileges locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00564,
            "epssPercentile": 0.44781,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-esu-kb5051974",
      "slug": "microsoft-2025-03-esu-kb5051974",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5051974",
      "title": "Deploy Microsoft ESU security update KB5051974",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5051974",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Windows 10 Version 22H2 for 32-bit Systems, Windows 10 Version 22H2 for ARM64-based Systems, Windows 10 Version 22H2 for x64-based Systems",
      "platform": "ESU",
      "release_version": "10.0.19045.5487",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.5,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-26634",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows 10 Version 22H2 for 32-bit Systems, Windows 10 Version 22H2 for ARM64-based Systems, Windows 10 Version 22H2 for x64-based Systems exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows 10 Version 22H2 for 32-bit Systems, Windows 10 Version 22H2 for ARM64-based Systems, Windows 10 Version 22H2 for x64-based Systems.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-26634"
        ],
        "details": [
          {
            "id": "CVE-2025-26634",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00649,
            "epssPercentile": 0.48843,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-esu-kb5051989",
      "slug": "microsoft-2025-03-esu-kb5051989",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5051989",
      "title": "Deploy Microsoft ESU security update KB5051989",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5051989",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Windows 11 Version 22H2 for ARM64-based Systems, Windows 11 Version 22H2 for x64-based Systems",
      "platform": "ESU",
      "release_version": "10.0.22621.4890",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.5,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-26634",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows 11 Version 22H2 for ARM64-based Systems, Windows 11 Version 22H2 for x64-based Systems exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows 11 Version 22H2 for ARM64-based Systems, Windows 11 Version 22H2 for x64-based Systems.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-26634"
        ],
        "details": [
          {
            "id": "CVE-2025-26634",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00649,
            "epssPercentile": 0.48843,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-esu-kb5053593",
      "slug": "microsoft-2025-03-esu-kb5053593",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5053593",
      "title": "Deploy Microsoft ESU security update KB5053593",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5053593",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation), Windows Server 2008 for 32-bit Systems Service Pack 2, plus 3 more",
      "platform": "ESU",
      "release_version": "1.000",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 4.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-21247",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation), Windows Server 2008 for 32-bit Systems Service Pack 2, plus 3 more exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation), Windows Server 2008 for 32-bit Systems Service Pack 2, plus 3 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-21247"
        ],
        "details": [
          {
            "id": "CVE-2025-21247",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03238,
            "epssPercentile": 0.87457,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-esu-kb5053602",
      "slug": "microsoft-2025-03-esu-kb5053602",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5053602",
      "title": "Deploy Microsoft ESU security update KB5053602",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5053602",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Windows 11 Version 22H2 for ARM64-based Systems, Windows 11 Version 22H2 for x64-based Systems",
      "platform": "ESU",
      "release_version": "10.0.22621.5039",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-26645",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows 11 Version 22H2 for ARM64-based Systems, Windows 11 Version 22H2 for x64-based Systems exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 32 linked CVEs for Windows 11 Version 22H2 for ARM64-based Systems, Windows 11 Version 22H2 for x64-based Systems. Microsoft reports exploitation for CVE-2025-24984, CVE-2025-24985, CVE-2025-24991, CVE-2025-24993, CVE-2025-26633.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 32,
        "ids": [
          "CVE-2025-21180",
          "CVE-2025-21247",
          "CVE-2025-24035",
          "CVE-2025-24044",
          "CVE-2025-24046",
          "CVE-2025-24048",
          "CVE-2025-24050",
          "CVE-2025-24051",
          "CVE-2025-24054",
          "CVE-2025-24055",
          "CVE-2025-24056",
          "CVE-2025-24059",
          "CVE-2025-24061",
          "CVE-2025-24066",
          "CVE-2025-24067",
          "CVE-2025-24071",
          "CVE-2025-24072",
          "CVE-2025-24076",
          "CVE-2025-24084",
          "CVE-2025-24984",
          "CVE-2025-24985",
          "CVE-2025-24987",
          "CVE-2025-24988",
          "CVE-2025-24991",
          "CVE-2025-24992",
          "CVE-2025-24993",
          "CVE-2025-24994",
          "CVE-2025-24995",
          "CVE-2025-24996",
          "CVE-2025-24997",
          "CVE-2025-26633",
          "CVE-2025-26645"
        ],
        "details": [
          {
            "id": "CVE-2025-21180",
            "title": "Windows exFAT File System Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows exFAT File System allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58294,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21247",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03238,
            "epssPercentile": 0.87457,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24035",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01825,
            "epssPercentile": 0.77382,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24044",
            "title": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00584,
            "epssPercentile": 0.45776,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24046",
            "title": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24048",
            "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43118,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24050",
            "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24051",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01578,
            "epssPercentile": 0.73854,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24054",
            "title": "Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-04-17.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.58909,
            "epssPercentile": 0.99044,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Mitigation available",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-05-08 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24055",
            "title": "Windows USB Video Class System Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to disclose information with a physical attack.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00854,
            "epssPercentile": 0.55945,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24056",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Server allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01673,
            "epssPercentile": 0.75274,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24059",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Incorrect conversion between numeric types in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43118,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24061",
            "title": "Windows Mark of the Web Security Feature Bypass Vulnerability",
            "summary": "Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01183,
            "epssPercentile": 0.65719,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24066",
            "title": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00698,
            "epssPercentile": 0.50755,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24067",
            "title": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00698,
            "epssPercentile": 0.50755,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24071",
            "title": "Microsoft Windows File Explorer Spoofing Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.24638,
            "epssPercentile": 0.97736,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Mitigation available",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "Medium technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24072",
            "title": "Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24076",
            "title": "Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03151,
            "epssPercentile": 0.87092,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24084",
            "title": "Windows Subsystem for Linux (WSL2) Kernel Remote Code Execution Vulnerability",
            "summary": "Untrusted pointer dereference in Windows Subsystem for Linux allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00684,
            "epssPercentile": 0.50268,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24984",
            "title": "Microsoft Windows NTFS Information Disclosure Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulnerability that allows an unauthorized attacker to disclose information with a physical attack. An attacker who successfully exploited this vulnerability could potentially read portions of heap memory.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01956,
            "epssPercentile": 0.78953,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24985",
            "title": "Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability",
            "summary": "Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.03846,
            "epssPercentile": 0.89435,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24987",
            "title": "Windows USB Video Class System Driver Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49653,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24988",
            "title": "Windows USB Video Class System Driver Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49653,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24991",
            "title": "Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01979,
            "epssPercentile": 0.79196,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24992",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01047,
            "epssPercentile": 0.61952,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24993",
            "title": "Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02173,
            "epssPercentile": 0.81117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24994",
            "title": "Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01166,
            "epssPercentile": 0.6525,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24995",
            "title": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00572,
            "epssPercentile": 0.4517,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24996",
            "title": "NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01292,
            "epssPercentile": 0.68377,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24997",
            "title": "DirectX Graphics Kernel File Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows Kernel Memory allows an authorized attacker to deny service locally.",
            "score": 4.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00593,
            "epssPercentile": 0.46191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-26633",
            "title": "Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability",
            "summary": "Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11. Known ransomware campaign use is recorded.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.30391,
            "epssPercentile": 0.98108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-26645",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03377,
            "epssPercentile": 0.87972,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-esu-kb5053606",
      "slug": "microsoft-2025-03-esu-kb5053606",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5053606",
      "title": "Deploy Microsoft ESU security update KB5053606",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5053606",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Windows 10 Version 22H2 for 32-bit Systems, Windows 10 Version 22H2 for ARM64-based Systems, Windows 10 Version 22H2 for x64-based Systems",
      "platform": "ESU",
      "release_version": "10.0.19045.5608",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-26645",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows 10 Version 22H2 for 32-bit Systems, Windows 10 Version 22H2 for ARM64-based Systems, Windows 10 Version 22H2 for x64-based Systems exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 29 linked CVEs for Windows 10 Version 22H2 for 32-bit Systems, Windows 10 Version 22H2 for ARM64-based Systems, Windows 10 Version 22H2 for x64-based Systems. Microsoft reports exploitation for CVE-2025-24984, CVE-2025-24985, CVE-2025-24991, CVE-2025-24993, CVE-2025-26633.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 29,
        "ids": [
          "CVE-2025-21180",
          "CVE-2025-21247",
          "CVE-2025-24035",
          "CVE-2025-24044",
          "CVE-2025-24046",
          "CVE-2025-24048",
          "CVE-2025-24050",
          "CVE-2025-24051",
          "CVE-2025-24054",
          "CVE-2025-24055",
          "CVE-2025-24056",
          "CVE-2025-24059",
          "CVE-2025-24061",
          "CVE-2025-24066",
          "CVE-2025-24067",
          "CVE-2025-24071",
          "CVE-2025-24072",
          "CVE-2025-24984",
          "CVE-2025-24985",
          "CVE-2025-24987",
          "CVE-2025-24988",
          "CVE-2025-24991",
          "CVE-2025-24992",
          "CVE-2025-24993",
          "CVE-2025-24995",
          "CVE-2025-24996",
          "CVE-2025-24997",
          "CVE-2025-26633",
          "CVE-2025-26645"
        ],
        "details": [
          {
            "id": "CVE-2025-21180",
            "title": "Windows exFAT File System Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows exFAT File System allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58294,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21247",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03238,
            "epssPercentile": 0.87457,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24035",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01825,
            "epssPercentile": 0.77382,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24044",
            "title": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00584,
            "epssPercentile": 0.45776,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24046",
            "title": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24048",
            "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43118,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24050",
            "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24051",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01578,
            "epssPercentile": 0.73854,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24054",
            "title": "Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-04-17.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.58909,
            "epssPercentile": 0.99044,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Mitigation available",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-05-08 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24055",
            "title": "Windows USB Video Class System Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to disclose information with a physical attack.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00854,
            "epssPercentile": 0.55945,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24056",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Server allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01673,
            "epssPercentile": 0.75274,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24059",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Incorrect conversion between numeric types in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43118,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24061",
            "title": "Windows Mark of the Web Security Feature Bypass Vulnerability",
            "summary": "Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01183,
            "epssPercentile": 0.65719,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24066",
            "title": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00698,
            "epssPercentile": 0.50755,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24067",
            "title": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00698,
            "epssPercentile": 0.50755,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24071",
            "title": "Microsoft Windows File Explorer Spoofing Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.24638,
            "epssPercentile": 0.97736,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Mitigation available",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "Medium technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24072",
            "title": "Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24984",
            "title": "Microsoft Windows NTFS Information Disclosure Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulnerability that allows an unauthorized attacker to disclose information with a physical attack. An attacker who successfully exploited this vulnerability could potentially read portions of heap memory.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01956,
            "epssPercentile": 0.78953,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24985",
            "title": "Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability",
            "summary": "Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.03846,
            "epssPercentile": 0.89435,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24987",
            "title": "Windows USB Video Class System Driver Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49653,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24988",
            "title": "Windows USB Video Class System Driver Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49653,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24991",
            "title": "Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01979,
            "epssPercentile": 0.79196,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24992",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01047,
            "epssPercentile": 0.61952,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24993",
            "title": "Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02173,
            "epssPercentile": 0.81117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24995",
            "title": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00572,
            "epssPercentile": 0.4517,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24996",
            "title": "NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01292,
            "epssPercentile": 0.68377,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24997",
            "title": "DirectX Graphics Kernel File Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows Kernel Memory allows an authorized attacker to deny service locally.",
            "score": 4.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00593,
            "epssPercentile": 0.46191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-26633",
            "title": "Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability",
            "summary": "Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11. Known ransomware campaign use is recorded.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.30391,
            "epssPercentile": 0.98108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-26645",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03377,
            "epssPercentile": 0.87972,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-esu-kb5053620",
      "slug": "microsoft-2025-03-esu-kb5053620",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5053620",
      "title": "Deploy Microsoft ESU security update KB5053620",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5053620",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)",
      "platform": "ESU",
      "release_version": "6.1.7601.27618",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-26645",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 20 linked CVEs for Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation). Microsoft reports exploitation for CVE-2025-24983, CVE-2025-24985, CVE-2025-24991, CVE-2025-24993, CVE-2025-26633.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 20,
        "ids": [
          "CVE-2025-21180",
          "CVE-2025-21247",
          "CVE-2025-24035",
          "CVE-2025-24051",
          "CVE-2025-24054",
          "CVE-2025-24055",
          "CVE-2025-24056",
          "CVE-2025-24059",
          "CVE-2025-24064",
          "CVE-2025-24072",
          "CVE-2025-24983",
          "CVE-2025-24985",
          "CVE-2025-24987",
          "CVE-2025-24988",
          "CVE-2025-24991",
          "CVE-2025-24992",
          "CVE-2025-24993",
          "CVE-2025-24996",
          "CVE-2025-26633",
          "CVE-2025-26645"
        ],
        "details": [
          {
            "id": "CVE-2025-21180",
            "title": "Windows exFAT File System Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows exFAT File System allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58294,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21247",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03238,
            "epssPercentile": 0.87457,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24035",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01825,
            "epssPercentile": 0.77382,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24051",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01578,
            "epssPercentile": 0.73854,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24054",
            "title": "Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-04-17.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.58909,
            "epssPercentile": 0.99044,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Mitigation available",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-05-08 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24055",
            "title": "Windows USB Video Class System Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to disclose information with a physical attack.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00854,
            "epssPercentile": 0.55945,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24056",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Server allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01673,
            "epssPercentile": 0.75274,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24059",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Incorrect conversion between numeric types in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43118,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24064",
            "title": "Windows Domain Name Service Remote Code Execution Vulnerability",
            "summary": "Use after free in DNS Server allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01369,
            "epssPercentile": 0.70063,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24072",
            "title": "Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24983",
            "title": "Microsoft Windows Win32k Use-After-Free Vulnerability",
            "summary": "Microsoft Windows Win32 Kernel Subsystem contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01348,
            "epssPercentile": 0.69617,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24985",
            "title": "Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability",
            "summary": "Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.03846,
            "epssPercentile": 0.89435,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24987",
            "title": "Windows USB Video Class System Driver Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49653,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24988",
            "title": "Windows USB Video Class System Driver Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49653,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24991",
            "title": "Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01979,
            "epssPercentile": 0.79196,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24992",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01047,
            "epssPercentile": 0.61952,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24993",
            "title": "Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02173,
            "epssPercentile": 0.81117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24996",
            "title": "NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01292,
            "epssPercentile": 0.68377,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-26633",
            "title": "Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability",
            "summary": "Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11. Known ransomware campaign use is recorded.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.30391,
            "epssPercentile": 0.98108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-26645",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03377,
            "epssPercentile": 0.87972,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-esu-kb5053627",
      "slug": "microsoft-2025-03-esu-kb5053627",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5053627",
      "title": "Deploy Microsoft ESU security update KB5053627",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5053627",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)",
      "platform": "ESU",
      "release_version": "6.1.7601.27618",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-26645",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 20 linked CVEs for Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation). Microsoft reports exploitation for CVE-2025-24983, CVE-2025-24985, CVE-2025-24991, CVE-2025-24993, CVE-2025-26633.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 20,
        "ids": [
          "CVE-2025-21180",
          "CVE-2025-21247",
          "CVE-2025-24035",
          "CVE-2025-24051",
          "CVE-2025-24054",
          "CVE-2025-24055",
          "CVE-2025-24056",
          "CVE-2025-24059",
          "CVE-2025-24064",
          "CVE-2025-24072",
          "CVE-2025-24983",
          "CVE-2025-24985",
          "CVE-2025-24987",
          "CVE-2025-24988",
          "CVE-2025-24991",
          "CVE-2025-24992",
          "CVE-2025-24993",
          "CVE-2025-24996",
          "CVE-2025-26633",
          "CVE-2025-26645"
        ],
        "details": [
          {
            "id": "CVE-2025-21180",
            "title": "Windows exFAT File System Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows exFAT File System allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58294,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21247",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03238,
            "epssPercentile": 0.87457,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24035",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01825,
            "epssPercentile": 0.77382,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24051",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01578,
            "epssPercentile": 0.73854,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24054",
            "title": "Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-04-17.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.58909,
            "epssPercentile": 0.99044,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Mitigation available",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-05-08 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24055",
            "title": "Windows USB Video Class System Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to disclose information with a physical attack.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00854,
            "epssPercentile": 0.55945,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24056",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Server allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01673,
            "epssPercentile": 0.75274,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24059",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Incorrect conversion between numeric types in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43118,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24064",
            "title": "Windows Domain Name Service Remote Code Execution Vulnerability",
            "summary": "Use after free in DNS Server allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01369,
            "epssPercentile": 0.70063,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24072",
            "title": "Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24983",
            "title": "Microsoft Windows Win32k Use-After-Free Vulnerability",
            "summary": "Microsoft Windows Win32 Kernel Subsystem contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01348,
            "epssPercentile": 0.69617,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24985",
            "title": "Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability",
            "summary": "Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.03846,
            "epssPercentile": 0.89435,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24987",
            "title": "Windows USB Video Class System Driver Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49653,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24988",
            "title": "Windows USB Video Class System Driver Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49653,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24991",
            "title": "Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01979,
            "epssPercentile": 0.79196,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24992",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01047,
            "epssPercentile": 0.61952,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24993",
            "title": "Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02173,
            "epssPercentile": 0.81117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24996",
            "title": "NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01292,
            "epssPercentile": 0.68377,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-26633",
            "title": "Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability",
            "summary": "Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11. Known ransomware campaign use is recorded.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.30391,
            "epssPercentile": 0.98108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-26645",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03377,
            "epssPercentile": 0.87972,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-esu-kb5053886",
      "slug": "microsoft-2025-03-esu-kb5053886",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5053886",
      "title": "Deploy Microsoft ESU security update KB5053886",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5053886",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Windows Server 2012, Windows Server 2012 (Server Core installation)",
      "platform": "ESU",
      "release_version": "6.2.9200.25368",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-26645",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows Server 2012, Windows Server 2012 (Server Core installation) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 23 linked CVEs for Windows Server 2012, Windows Server 2012 (Server Core installation). Microsoft reports exploitation for CVE-2025-24983, CVE-2025-24984, CVE-2025-24985, CVE-2025-24991, CVE-2025-24993, CVE-2025-26633.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 23,
        "ids": [
          "CVE-2025-21180",
          "CVE-2025-21247",
          "CVE-2025-24035",
          "CVE-2025-24044",
          "CVE-2025-24045",
          "CVE-2025-24051",
          "CVE-2025-24054",
          "CVE-2025-24055",
          "CVE-2025-24056",
          "CVE-2025-24059",
          "CVE-2025-24064",
          "CVE-2025-24072",
          "CVE-2025-24983",
          "CVE-2025-24984",
          "CVE-2025-24985",
          "CVE-2025-24987",
          "CVE-2025-24988",
          "CVE-2025-24991",
          "CVE-2025-24992",
          "CVE-2025-24993",
          "CVE-2025-24996",
          "CVE-2025-26633",
          "CVE-2025-26645"
        ],
        "details": [
          {
            "id": "CVE-2025-21180",
            "title": "Windows exFAT File System Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows exFAT File System allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58294,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21247",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03238,
            "epssPercentile": 0.87457,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24035",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01825,
            "epssPercentile": 0.77382,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24044",
            "title": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00584,
            "epssPercentile": 0.45776,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24045",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01417,
            "epssPercentile": 0.71019,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24051",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01578,
            "epssPercentile": 0.73854,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24054",
            "title": "Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-04-17.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.58909,
            "epssPercentile": 0.99044,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Mitigation available",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-05-08 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24055",
            "title": "Windows USB Video Class System Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to disclose information with a physical attack.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00854,
            "epssPercentile": 0.55945,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24056",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Server allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01673,
            "epssPercentile": 0.75274,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24059",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Incorrect conversion between numeric types in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43118,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24064",
            "title": "Windows Domain Name Service Remote Code Execution Vulnerability",
            "summary": "Use after free in DNS Server allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01369,
            "epssPercentile": 0.70063,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24072",
            "title": "Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24983",
            "title": "Microsoft Windows Win32k Use-After-Free Vulnerability",
            "summary": "Microsoft Windows Win32 Kernel Subsystem contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01348,
            "epssPercentile": 0.69617,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24984",
            "title": "Microsoft Windows NTFS Information Disclosure Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulnerability that allows an unauthorized attacker to disclose information with a physical attack. An attacker who successfully exploited this vulnerability could potentially read portions of heap memory.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01956,
            "epssPercentile": 0.78953,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24985",
            "title": "Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability",
            "summary": "Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.03846,
            "epssPercentile": 0.89435,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24987",
            "title": "Windows USB Video Class System Driver Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49653,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24988",
            "title": "Windows USB Video Class System Driver Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49653,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24991",
            "title": "Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01979,
            "epssPercentile": 0.79196,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24992",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01047,
            "epssPercentile": 0.61952,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24993",
            "title": "Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02173,
            "epssPercentile": 0.81117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24996",
            "title": "NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01292,
            "epssPercentile": 0.68377,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-26633",
            "title": "Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability",
            "summary": "Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11. Known ransomware campaign use is recorded.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.30391,
            "epssPercentile": 0.98108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-26645",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03377,
            "epssPercentile": 0.87972,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-esu-kb5053887",
      "slug": "microsoft-2025-03-esu-kb5053887",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5053887",
      "title": "Deploy Microsoft ESU security update KB5053887",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5053887",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation)",
      "platform": "ESU",
      "release_version": "6.3.9600.22470",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-26645",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 24 linked CVEs for Windows Server 2012 R2, Windows Server 2012 R2 (Server Core installation). Microsoft reports exploitation for CVE-2025-24983, CVE-2025-24984, CVE-2025-24985, CVE-2025-24991, CVE-2025-24993, CVE-2025-26633.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 24,
        "ids": [
          "CVE-2025-21180",
          "CVE-2025-21247",
          "CVE-2025-24035",
          "CVE-2025-24044",
          "CVE-2025-24045",
          "CVE-2025-24051",
          "CVE-2025-24054",
          "CVE-2025-24055",
          "CVE-2025-24056",
          "CVE-2025-24059",
          "CVE-2025-24064",
          "CVE-2025-24071",
          "CVE-2025-24072",
          "CVE-2025-24983",
          "CVE-2025-24984",
          "CVE-2025-24985",
          "CVE-2025-24987",
          "CVE-2025-24988",
          "CVE-2025-24991",
          "CVE-2025-24992",
          "CVE-2025-24993",
          "CVE-2025-24996",
          "CVE-2025-26633",
          "CVE-2025-26645"
        ],
        "details": [
          {
            "id": "CVE-2025-21180",
            "title": "Windows exFAT File System Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows exFAT File System allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58294,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21247",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03238,
            "epssPercentile": 0.87457,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24035",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01825,
            "epssPercentile": 0.77382,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24044",
            "title": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00584,
            "epssPercentile": 0.45776,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24045",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01417,
            "epssPercentile": 0.71019,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24051",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01578,
            "epssPercentile": 0.73854,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24054",
            "title": "Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-04-17.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.58909,
            "epssPercentile": 0.99044,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Mitigation available",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-05-08 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24055",
            "title": "Windows USB Video Class System Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to disclose information with a physical attack.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00854,
            "epssPercentile": 0.55945,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24056",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Server allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01673,
            "epssPercentile": 0.75274,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24059",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Incorrect conversion between numeric types in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43118,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24064",
            "title": "Windows Domain Name Service Remote Code Execution Vulnerability",
            "summary": "Use after free in DNS Server allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01369,
            "epssPercentile": 0.70063,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24071",
            "title": "Microsoft Windows File Explorer Spoofing Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.24638,
            "epssPercentile": 0.97736,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Mitigation available",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "Medium technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24072",
            "title": "Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24983",
            "title": "Microsoft Windows Win32k Use-After-Free Vulnerability",
            "summary": "Microsoft Windows Win32 Kernel Subsystem contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01348,
            "epssPercentile": 0.69617,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24984",
            "title": "Microsoft Windows NTFS Information Disclosure Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulnerability that allows an unauthorized attacker to disclose information with a physical attack. An attacker who successfully exploited this vulnerability could potentially read portions of heap memory.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01956,
            "epssPercentile": 0.78953,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24985",
            "title": "Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability",
            "summary": "Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.03846,
            "epssPercentile": 0.89435,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24987",
            "title": "Windows USB Video Class System Driver Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49653,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24988",
            "title": "Windows USB Video Class System Driver Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49653,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24991",
            "title": "Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01979,
            "epssPercentile": 0.79196,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24992",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01047,
            "epssPercentile": 0.61952,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24993",
            "title": "Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02173,
            "epssPercentile": 0.81117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24996",
            "title": "NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01292,
            "epssPercentile": 0.68377,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-26633",
            "title": "Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability",
            "summary": "Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11. Known ransomware campaign use is recorded.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.30391,
            "epssPercentile": 0.98108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-26645",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03377,
            "epssPercentile": 0.87972,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-esu-kb5053888",
      "slug": "microsoft-2025-03-esu-kb5053888",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5053888",
      "title": "Deploy Microsoft ESU security update KB5053888",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5053888",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more",
      "platform": "ESU",
      "release_version": "6.0.6003.23168",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-26645",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 18 linked CVEs for Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more. Microsoft reports exploitation for CVE-2025-24983, CVE-2025-24985, CVE-2025-24991, CVE-2025-24993, CVE-2025-26633.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 18,
        "ids": [
          "CVE-2025-21180",
          "CVE-2025-21247",
          "CVE-2025-24035",
          "CVE-2025-24051",
          "CVE-2025-24055",
          "CVE-2025-24056",
          "CVE-2025-24059",
          "CVE-2025-24064",
          "CVE-2025-24072",
          "CVE-2025-24983",
          "CVE-2025-24985",
          "CVE-2025-24987",
          "CVE-2025-24988",
          "CVE-2025-24991",
          "CVE-2025-24992",
          "CVE-2025-24993",
          "CVE-2025-26633",
          "CVE-2025-26645"
        ],
        "details": [
          {
            "id": "CVE-2025-21180",
            "title": "Windows exFAT File System Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows exFAT File System allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58294,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21247",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03238,
            "epssPercentile": 0.87457,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24035",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01825,
            "epssPercentile": 0.77382,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24051",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01578,
            "epssPercentile": 0.73854,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24055",
            "title": "Windows USB Video Class System Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to disclose information with a physical attack.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00854,
            "epssPercentile": 0.55945,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24056",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Server allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01673,
            "epssPercentile": 0.75274,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24059",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Incorrect conversion between numeric types in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43118,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24064",
            "title": "Windows Domain Name Service Remote Code Execution Vulnerability",
            "summary": "Use after free in DNS Server allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01369,
            "epssPercentile": 0.70063,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24072",
            "title": "Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24983",
            "title": "Microsoft Windows Win32k Use-After-Free Vulnerability",
            "summary": "Microsoft Windows Win32 Kernel Subsystem contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01348,
            "epssPercentile": 0.69617,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24985",
            "title": "Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability",
            "summary": "Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.03846,
            "epssPercentile": 0.89435,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24987",
            "title": "Windows USB Video Class System Driver Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49653,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24988",
            "title": "Windows USB Video Class System Driver Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49653,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24991",
            "title": "Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01979,
            "epssPercentile": 0.79196,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24992",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01047,
            "epssPercentile": 0.61952,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24993",
            "title": "Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02173,
            "epssPercentile": 0.81117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-26633",
            "title": "Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability",
            "summary": "Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11. Known ransomware campaign use is recorded.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.30391,
            "epssPercentile": 0.98108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-26645",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03377,
            "epssPercentile": 0.87972,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-esu-kb5053995",
      "slug": "microsoft-2025-03-esu-kb5053995",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5053995",
      "title": "Deploy Microsoft ESU security update KB5053995",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5053995",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more",
      "platform": "ESU",
      "release_version": "6.0.6003.23168",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-26645",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 18 linked CVEs for Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation), Windows Server 2008 for x64-based Systems Service Pack 2, plus 1 more. Microsoft reports exploitation for CVE-2025-24983, CVE-2025-24985, CVE-2025-24991, CVE-2025-24993, CVE-2025-26633.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 18,
        "ids": [
          "CVE-2025-21180",
          "CVE-2025-21247",
          "CVE-2025-24035",
          "CVE-2025-24051",
          "CVE-2025-24055",
          "CVE-2025-24056",
          "CVE-2025-24059",
          "CVE-2025-24064",
          "CVE-2025-24072",
          "CVE-2025-24983",
          "CVE-2025-24985",
          "CVE-2025-24987",
          "CVE-2025-24988",
          "CVE-2025-24991",
          "CVE-2025-24992",
          "CVE-2025-24993",
          "CVE-2025-26633",
          "CVE-2025-26645"
        ],
        "details": [
          {
            "id": "CVE-2025-21180",
            "title": "Windows exFAT File System Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows exFAT File System allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58294,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21247",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03238,
            "epssPercentile": 0.87457,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24035",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01825,
            "epssPercentile": 0.77382,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24051",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01578,
            "epssPercentile": 0.73854,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24055",
            "title": "Windows USB Video Class System Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to disclose information with a physical attack.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00854,
            "epssPercentile": 0.55945,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24056",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Server allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01673,
            "epssPercentile": 0.75274,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24059",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Incorrect conversion between numeric types in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43118,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24064",
            "title": "Windows Domain Name Service Remote Code Execution Vulnerability",
            "summary": "Use after free in DNS Server allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01369,
            "epssPercentile": 0.70063,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24072",
            "title": "Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24983",
            "title": "Microsoft Windows Win32k Use-After-Free Vulnerability",
            "summary": "Microsoft Windows Win32 Kernel Subsystem contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01348,
            "epssPercentile": 0.69617,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24985",
            "title": "Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability",
            "summary": "Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.03846,
            "epssPercentile": 0.89435,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24987",
            "title": "Windows USB Video Class System Driver Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49653,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24988",
            "title": "Windows USB Video Class System Driver Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49653,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24991",
            "title": "Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01979,
            "epssPercentile": 0.79196,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24992",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01047,
            "epssPercentile": 0.61952,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24993",
            "title": "Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02173,
            "epssPercentile": 0.81117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-26633",
            "title": "Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability",
            "summary": "Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11. Known ransomware campaign use is recorded.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.30391,
            "epssPercentile": 0.98108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-26645",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03377,
            "epssPercentile": 0.87972,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-microsoft-office-kb5002662",
      "slug": "microsoft-2025-03-microsoft-office-kb5002662",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002662",
      "title": "Deploy Microsoft Microsoft Office security update KB5002662",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002662",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Microsoft Word 2016 (32-bit edition), Microsoft Word 2016 (64-bit edition)",
      "platform": "Microsoft Office",
      "release_version": "16.0.18526.20080",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-24079",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Word 2016 (32-bit edition), Microsoft Word 2016 (64-bit edition) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 2 linked CVEs for Microsoft Word 2016 (32-bit edition), Microsoft Word 2016 (64-bit edition).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 2,
        "ids": [
          "CVE-2025-24078",
          "CVE-2025-24079"
        ],
        "details": [
          {
            "id": "CVE-2025-24078",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00561,
            "epssPercentile": 0.44593,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24079",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00685,
            "epssPercentile": 0.50331,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-microsoft-office-kb5002690",
      "slug": "microsoft-2025-03-microsoft-office-kb5002690",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002690",
      "title": "Deploy Microsoft Microsoft Office security update KB5002690",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002690",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Office Online Server",
      "platform": "Microsoft Office",
      "release_version": "16.0.10416.20073",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-24082",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Office Online Server exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Office Online Server.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 3,
        "ids": [
          "CVE-2025-24075",
          "CVE-2025-24081",
          "CVE-2025-24082"
        ],
        "details": [
          {
            "id": "CVE-2025-24075",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00675,
            "epssPercentile": 0.49902,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24081",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00685,
            "epssPercentile": 0.50331,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24082",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.007,
            "epssPercentile": 0.50853,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-microsoft-office-kb5002693",
      "slug": "microsoft-2025-03-microsoft-office-kb5002693",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002693",
      "title": "Deploy Microsoft Microsoft Office security update KB5002693",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002693",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition)",
      "platform": "Microsoft Office",
      "release_version": "16.0.5491.1001",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-24083",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft Office 2016 (32-bit edition), Microsoft Office 2016 (64-bit edition).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 3,
        "ids": [
          "CVE-2025-24057",
          "CVE-2025-24080",
          "CVE-2025-24083"
        ],
        "details": [
          {
            "id": "CVE-2025-24057",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00952,
            "epssPercentile": 0.59015,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24080",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00685,
            "epssPercentile": 0.50331,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24083",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00685,
            "epssPercentile": 0.50331,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-microsoft-office-kb5002694",
      "slug": "microsoft-2025-03-microsoft-office-kb5002694",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002694",
      "title": "Deploy Microsoft Microsoft Office security update KB5002694",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002694",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Microsoft Excel 2016 (32-bit edition), Microsoft Excel 2016 (64-bit edition)",
      "platform": "Microsoft Office",
      "release_version": "16.0.5491.1000",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-24081",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Excel 2016 (32-bit edition), Microsoft Excel 2016 (64-bit edition) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Excel 2016 (32-bit edition), Microsoft Excel 2016 (64-bit edition).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-24081"
        ],
        "details": [
          {
            "id": "CVE-2025-24081",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00685,
            "epssPercentile": 0.50331,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-microsoft-office-kb5002696",
      "slug": "microsoft-2025-03-microsoft-office-kb5002696",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002696",
      "title": "Deploy Microsoft Microsoft Office security update KB5002696",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002696",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Microsoft Excel 2016 (32-bit edition), Microsoft Excel 2016 (64-bit edition)",
      "platform": "Microsoft Office",
      "release_version": "16.0.5491.1000",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-24082",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Excel 2016 (32-bit edition), Microsoft Excel 2016 (64-bit edition) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft Excel 2016 (32-bit edition), Microsoft Excel 2016 (64-bit edition).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 3,
        "ids": [
          "CVE-2025-24075",
          "CVE-2025-24081",
          "CVE-2025-24082"
        ],
        "details": [
          {
            "id": "CVE-2025-24075",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00675,
            "epssPercentile": 0.49902,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24081",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00685,
            "epssPercentile": 0.50331,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24082",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.007,
            "epssPercentile": 0.50853,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-microsoft-office-kb5002697",
      "slug": "microsoft-2025-03-microsoft-office-kb5002697",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5002697",
      "title": "Deploy Microsoft Microsoft Office security update KB5002697",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5002697",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Microsoft Access 2016 (32-bit edition), Microsoft Access 2016 (64-bit edition)",
      "platform": "Microsoft Office",
      "release_version": "16.0.5491.1001",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-26630",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Access 2016 (32-bit edition), Microsoft Access 2016 (64-bit edition) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Access 2016 (32-bit edition), Microsoft Access 2016 (64-bit edition). Microsoft marks CVE-2025-26630 as publicly disclosed, without that disclosure alone changing the BlackTree action window.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-26630"
        ],
        "details": [
          {
            "id": "CVE-2025-26630",
            "title": "Microsoft Access Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Access allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00952,
            "epssPercentile": 0.59015,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-microsoft-office-msrc-2025-03-microsoft-office-click-to-run-microsoft-365-apps-for-enterprise-for-32-bit-systems-microsoft-365-apps-for-enterprise-for-64-bit-systems-micr",
      "slug": "microsoft-2025-03-microsoft-office-msrc-2025-03-microsoft-office-click-to-run-microsoft-365-apps-for-enterprise-for-32-bit-systems-microsoft-365-apps-for-enterprise-for-64-bit-systems-micr",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-03-microsoft-office-click-to-run",
      "title": "Deploy Microsoft Microsoft Office update for Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office 2019 for 32-bit editions, plus 5 more",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://msrc.microsoft.com/update-guide/releaseNote/2025-Mar",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office 2019 for 32-bit editions, plus 5 more",
      "platform": "Microsoft Office",
      "release_version": "https://aka.ms/OfficeSecurityReleases",
      "action_type": "deploy-patch",
      "restart_required": "no",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-26630",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "The reviewed source does not require a restart.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office 2019 for 32-bit editions, plus 5 more exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 11 linked CVEs for Microsoft 365 Apps for Enterprise for 32-bit Systems, Microsoft 365 Apps for Enterprise for 64-bit Systems, Microsoft Office 2019 for 32-bit editions, plus 5 more. Microsoft marks CVE-2025-26630 as publicly disclosed, without that disclosure alone changing the BlackTree action window.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 11,
        "ids": [
          "CVE-2025-24057",
          "CVE-2025-24075",
          "CVE-2025-24077",
          "CVE-2025-24078",
          "CVE-2025-24079",
          "CVE-2025-24080",
          "CVE-2025-24081",
          "CVE-2025-24082",
          "CVE-2025-24083",
          "CVE-2025-26629",
          "CVE-2025-26630"
        ],
        "details": [
          {
            "id": "CVE-2025-24057",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00952,
            "epssPercentile": 0.59015,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24075",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00675,
            "epssPercentile": 0.49902,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24077",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00575,
            "epssPercentile": 0.45332,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24078",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00561,
            "epssPercentile": 0.44593,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24079",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00685,
            "epssPercentile": 0.50331,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24080",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00685,
            "epssPercentile": 0.50331,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24081",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00685,
            "epssPercentile": 0.50331,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24082",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.007,
            "epssPercentile": 0.50853,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24083",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00685,
            "epssPercentile": 0.50331,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-26629",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00568,
            "epssPercentile": 0.44991,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-26630",
            "title": "Microsoft Access Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Access allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00952,
            "epssPercentile": 0.59015,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-microsoft-office-msrc-2025-03-microsoft-office-release-notes-microsoft-office-ltsc-for-mac-2021",
      "slug": "microsoft-2025-03-microsoft-office-msrc-2025-03-microsoft-office-release-notes-microsoft-office-ltsc-for-mac-2021",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-03-microsoft-office-release-notes",
      "title": "Deploy Microsoft Microsoft Office update for Microsoft Office LTSC for Mac 2021",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://go.microsoft.com/fwlink/p/?linkid=831049",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Microsoft Office LTSC for Mac 2021",
      "platform": "Microsoft Office",
      "release_version": "16.95.25030928",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-24083",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Office LTSC for Mac 2021 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 8 linked CVEs for Microsoft Office LTSC for Mac 2021.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 8,
        "ids": [
          "CVE-2025-24057",
          "CVE-2025-24075",
          "CVE-2025-24077",
          "CVE-2025-24078",
          "CVE-2025-24079",
          "CVE-2025-24081",
          "CVE-2025-24082",
          "CVE-2025-24083"
        ],
        "details": [
          {
            "id": "CVE-2025-24057",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00952,
            "epssPercentile": 0.59015,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24075",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00675,
            "epssPercentile": 0.49902,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24077",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00575,
            "epssPercentile": 0.45332,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24078",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00561,
            "epssPercentile": 0.44593,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24079",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00685,
            "epssPercentile": 0.50331,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24081",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00685,
            "epssPercentile": 0.50331,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24082",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.007,
            "epssPercentile": 0.50853,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24083",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00685,
            "epssPercentile": 0.50331,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-microsoft-office-msrc-2025-03-microsoft-office-release-notes-microsoft-office-ltsc-for-mac-2024",
      "slug": "microsoft-2025-03-microsoft-office-msrc-2025-03-microsoft-office-release-notes-microsoft-office-ltsc-for-mac-2024",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-03-microsoft-office-release-notes",
      "title": "Deploy Microsoft Microsoft Office update for Microsoft Office LTSC for Mac 2024",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://go.microsoft.com/fwlink/p/?linkid=831049",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Microsoft Office LTSC for Mac 2024",
      "platform": "Microsoft Office",
      "release_version": "16.95.25030928",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-24083",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Microsoft Office LTSC for Mac 2024 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 8 linked CVEs for Microsoft Office LTSC for Mac 2024.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 8,
        "ids": [
          "CVE-2025-24057",
          "CVE-2025-24075",
          "CVE-2025-24077",
          "CVE-2025-24078",
          "CVE-2025-24079",
          "CVE-2025-24081",
          "CVE-2025-24082",
          "CVE-2025-24083"
        ],
        "details": [
          {
            "id": "CVE-2025-24057",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00952,
            "epssPercentile": 0.59015,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24075",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00675,
            "epssPercentile": 0.49902,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24077",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00575,
            "epssPercentile": 0.45332,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24078",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00561,
            "epssPercentile": 0.44593,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24079",
            "title": "Microsoft Word Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00685,
            "epssPercentile": 0.50331,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24081",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00685,
            "epssPercentile": 0.50331,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24082",
            "title": "Microsoft Excel Remote Code Execution Vulnerability",
            "summary": "Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.007,
            "epssPercentile": 0.50853,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24083",
            "title": "Microsoft Office Remote Code Execution Vulnerability",
            "summary": "Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00685,
            "epssPercentile": 0.50331,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-windows-kb5051974",
      "slug": "microsoft-2025-03-windows-kb5051974",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5051974",
      "title": "Deploy Microsoft Windows security update KB5051974",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5051974",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems",
      "platform": "Windows",
      "release_version": "10.0.19044.5487",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.5,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-26634",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-26634"
        ],
        "details": [
          {
            "id": "CVE-2025-26634",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00649,
            "epssPercentile": 0.48843,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-windows-kb5051979",
      "slug": "microsoft-2025-03-windows-kb5051979",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5051979",
      "title": "Deploy Microsoft Windows security update KB5051979",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5051979",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Windows Server 2022, Windows Server 2022 (Server Core installation)",
      "platform": "Windows",
      "release_version": "10.0.20348.3207",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.5,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-26634",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows Server 2022, Windows Server 2022 (Server Core installation) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows Server 2022, Windows Server 2022 (Server Core installation).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-26634"
        ],
        "details": [
          {
            "id": "CVE-2025-26634",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00649,
            "epssPercentile": 0.48843,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-windows-kb5051980",
      "slug": "microsoft-2025-03-windows-kb5051980",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5051980",
      "title": "Deploy Microsoft Windows security update KB5051980",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5051980",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Windows Server 2022, 23H2 Edition (Server Core installation)",
      "platform": "Windows",
      "release_version": "10.0.25398.1425",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.5,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-26634",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows Server 2022, 23H2 Edition (Server Core installation) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows Server 2022, 23H2 Edition (Server Core installation).",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-26634"
        ],
        "details": [
          {
            "id": "CVE-2025-26634",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00649,
            "epssPercentile": 0.48843,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-windows-kb5051987",
      "slug": "microsoft-2025-03-windows-kb5051987",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5051987",
      "title": "Deploy Microsoft Windows security update KB5051987",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5051987",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, plus 1 more",
      "platform": "Windows",
      "release_version": "10.0.26100.3194",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.5,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-26634",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, plus 1 more exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, plus 1 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-26634"
        ],
        "details": [
          {
            "id": "CVE-2025-26634",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00649,
            "epssPercentile": 0.48843,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-windows-kb5051989",
      "slug": "microsoft-2025-03-windows-kb5051989",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5051989",
      "title": "Deploy Microsoft Windows security update KB5051989",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5051989",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Windows 11 Version 23H2 for ARM64-based Systems, Windows 11 Version 23H2 for x64-based Systems",
      "platform": "Windows",
      "release_version": "10.0.22631.4890",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.5,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-26634",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows 11 Version 23H2 for ARM64-based Systems, Windows 11 Version 23H2 for x64-based Systems exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows 11 Version 23H2 for ARM64-based Systems, Windows 11 Version 23H2 for x64-based Systems.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-26634"
        ],
        "details": [
          {
            "id": "CVE-2025-26634",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00649,
            "epssPercentile": 0.48843,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-windows-kb5052000",
      "slug": "microsoft-2025-03-windows-kb5052000",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5052000",
      "title": "Deploy Microsoft Windows security update KB5052000",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5052000",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, plus 1 more",
      "platform": "Windows",
      "release_version": "10.0.17763.6893",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.5,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-26634",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, plus 1 more exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, plus 1 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-26634"
        ],
        "details": [
          {
            "id": "CVE-2025-26634",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00649,
            "epssPercentile": 0.48843,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-windows-kb5052006",
      "slug": "microsoft-2025-03-windows-kb5052006",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5052006",
      "title": "Deploy Microsoft Windows security update KB5052006",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5052006",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Windows 10 Version 1607 for 32-bit Systems, Windows 10 Version 1607 for x64-based Systems, Windows Server 2016, plus 1 more",
      "platform": "Windows",
      "release_version": "10.0.14393.7785",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.5,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-26634",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows 10 Version 1607 for 32-bit Systems, Windows 10 Version 1607 for x64-based Systems, Windows Server 2016, plus 1 more exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows 10 Version 1607 for 32-bit Systems, Windows 10 Version 1607 for x64-based Systems, Windows Server 2016, plus 1 more.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-26634"
        ],
        "details": [
          {
            "id": "CVE-2025-26634",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00649,
            "epssPercentile": 0.48843,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-windows-kb5052040",
      "slug": "microsoft-2025-03-windows-kb5052040",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5052040",
      "title": "Deploy Microsoft Windows security update KB5052040",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5052040",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Windows 10 for 32-bit Systems, Windows 10 for x64-based Systems",
      "platform": "Windows",
      "release_version": "10.0.10240.20915",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Important",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.5,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-26634",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows 10 for 32-bit Systems, Windows 10 for x64-based Systems exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows 10 for 32-bit Systems, Windows 10 for x64-based Systems.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-26634"
        ],
        "details": [
          {
            "id": "CVE-2025-26634",
            "title": "Windows Core Messaging Elevation of Privileges Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges over a network.",
            "score": 7.5,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00649,
            "epssPercentile": 0.48843,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-windows-kb5053594",
      "slug": "microsoft-2025-03-windows-kb5053594",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5053594",
      "title": "Deploy Microsoft Windows security update KB5053594",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5053594",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Windows 10 Version 1607 for 32-bit Systems, Windows 10 Version 1607 for x64-based Systems, Windows Server 2016, plus 1 more",
      "platform": "Windows",
      "release_version": "10.0.14393.7876",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-26645",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows 10 Version 1607 for 32-bit Systems, Windows 10 Version 1607 for x64-based Systems, Windows Server 2016, plus 1 more exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 32 linked CVEs for Windows 10 Version 1607 for 32-bit Systems, Windows 10 Version 1607 for x64-based Systems, Windows Server 2016, plus 1 more. Microsoft reports exploitation for CVE-2025-24983, CVE-2025-24984, CVE-2025-24985, CVE-2025-24991, CVE-2025-24993, CVE-2025-26633.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 32,
        "ids": [
          "CVE-2025-21180",
          "CVE-2025-21247",
          "CVE-2025-24035",
          "CVE-2025-24044",
          "CVE-2025-24045",
          "CVE-2025-24046",
          "CVE-2025-24048",
          "CVE-2025-24050",
          "CVE-2025-24051",
          "CVE-2025-24054",
          "CVE-2025-24055",
          "CVE-2025-24056",
          "CVE-2025-24059",
          "CVE-2025-24061",
          "CVE-2025-24064",
          "CVE-2025-24066",
          "CVE-2025-24067",
          "CVE-2025-24071",
          "CVE-2025-24072",
          "CVE-2025-24983",
          "CVE-2025-24984",
          "CVE-2025-24985",
          "CVE-2025-24987",
          "CVE-2025-24988",
          "CVE-2025-24991",
          "CVE-2025-24992",
          "CVE-2025-24993",
          "CVE-2025-24995",
          "CVE-2025-24996",
          "CVE-2025-25008",
          "CVE-2025-26633",
          "CVE-2025-26645"
        ],
        "details": [
          {
            "id": "CVE-2025-21180",
            "title": "Windows exFAT File System Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows exFAT File System allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58294,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21247",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03238,
            "epssPercentile": 0.87457,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24035",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01825,
            "epssPercentile": 0.77382,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24044",
            "title": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00584,
            "epssPercentile": 0.45776,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24045",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01417,
            "epssPercentile": 0.71019,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24046",
            "title": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24048",
            "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43118,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24050",
            "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24051",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01578,
            "epssPercentile": 0.73854,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24054",
            "title": "Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-04-17.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.58909,
            "epssPercentile": 0.99044,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Mitigation available",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-05-08 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24055",
            "title": "Windows USB Video Class System Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to disclose information with a physical attack.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00854,
            "epssPercentile": 0.55945,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24056",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Server allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01673,
            "epssPercentile": 0.75274,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24059",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Incorrect conversion between numeric types in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43118,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24061",
            "title": "Windows Mark of the Web Security Feature Bypass Vulnerability",
            "summary": "Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01183,
            "epssPercentile": 0.65719,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24064",
            "title": "Windows Domain Name Service Remote Code Execution Vulnerability",
            "summary": "Use after free in DNS Server allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01369,
            "epssPercentile": 0.70063,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24066",
            "title": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00698,
            "epssPercentile": 0.50755,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24067",
            "title": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00698,
            "epssPercentile": 0.50755,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24071",
            "title": "Microsoft Windows File Explorer Spoofing Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.24638,
            "epssPercentile": 0.97736,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Mitigation available",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "Medium technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24072",
            "title": "Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24983",
            "title": "Microsoft Windows Win32k Use-After-Free Vulnerability",
            "summary": "Microsoft Windows Win32 Kernel Subsystem contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01348,
            "epssPercentile": 0.69617,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24984",
            "title": "Microsoft Windows NTFS Information Disclosure Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulnerability that allows an unauthorized attacker to disclose information with a physical attack. An attacker who successfully exploited this vulnerability could potentially read portions of heap memory.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01956,
            "epssPercentile": 0.78953,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24985",
            "title": "Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability",
            "summary": "Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.03846,
            "epssPercentile": 0.89435,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24987",
            "title": "Windows USB Video Class System Driver Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49653,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24988",
            "title": "Windows USB Video Class System Driver Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49653,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24991",
            "title": "Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01979,
            "epssPercentile": 0.79196,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24992",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01047,
            "epssPercentile": 0.61952,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24993",
            "title": "Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02173,
            "epssPercentile": 0.81117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24995",
            "title": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00572,
            "epssPercentile": 0.4517,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24996",
            "title": "NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01292,
            "epssPercentile": 0.68377,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-25008",
            "title": "Windows Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Microsoft Windows allows an authorized attacker to elevate privileges locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.006,
            "epssPercentile": 0.46563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-26633",
            "title": "Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability",
            "summary": "Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11. Known ransomware campaign use is recorded.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.30391,
            "epssPercentile": 0.98108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-26645",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03377,
            "epssPercentile": 0.87972,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-windows-kb5053596",
      "slug": "microsoft-2025-03-windows-kb5053596",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5053596",
      "title": "Deploy Microsoft Windows security update KB5053596",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5053596",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, plus 1 more",
      "platform": "Windows",
      "release_version": "10.0.17763.7009",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-26645",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, plus 1 more exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 31 linked CVEs for Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019, plus 1 more. Microsoft reports exploitation for CVE-2025-24984, CVE-2025-24985, CVE-2025-24991, CVE-2025-24993, CVE-2025-26633.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 31,
        "ids": [
          "CVE-2025-21180",
          "CVE-2025-21247",
          "CVE-2025-24035",
          "CVE-2025-24044",
          "CVE-2025-24045",
          "CVE-2025-24046",
          "CVE-2025-24048",
          "CVE-2025-24050",
          "CVE-2025-24051",
          "CVE-2025-24054",
          "CVE-2025-24055",
          "CVE-2025-24056",
          "CVE-2025-24059",
          "CVE-2025-24061",
          "CVE-2025-24064",
          "CVE-2025-24066",
          "CVE-2025-24067",
          "CVE-2025-24071",
          "CVE-2025-24072",
          "CVE-2025-24984",
          "CVE-2025-24985",
          "CVE-2025-24987",
          "CVE-2025-24988",
          "CVE-2025-24991",
          "CVE-2025-24992",
          "CVE-2025-24993",
          "CVE-2025-24995",
          "CVE-2025-24996",
          "CVE-2025-25008",
          "CVE-2025-26633",
          "CVE-2025-26645"
        ],
        "details": [
          {
            "id": "CVE-2025-21180",
            "title": "Windows exFAT File System Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows exFAT File System allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58294,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21247",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03238,
            "epssPercentile": 0.87457,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24035",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01825,
            "epssPercentile": 0.77382,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24044",
            "title": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00584,
            "epssPercentile": 0.45776,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24045",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01417,
            "epssPercentile": 0.71019,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24046",
            "title": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24048",
            "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43118,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24050",
            "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24051",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01578,
            "epssPercentile": 0.73854,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24054",
            "title": "Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-04-17.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.58909,
            "epssPercentile": 0.99044,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Mitigation available",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-05-08 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24055",
            "title": "Windows USB Video Class System Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to disclose information with a physical attack.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00854,
            "epssPercentile": 0.55945,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24056",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Server allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01673,
            "epssPercentile": 0.75274,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24059",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Incorrect conversion between numeric types in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43118,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24061",
            "title": "Windows Mark of the Web Security Feature Bypass Vulnerability",
            "summary": "Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01183,
            "epssPercentile": 0.65719,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24064",
            "title": "Windows Domain Name Service Remote Code Execution Vulnerability",
            "summary": "Use after free in DNS Server allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01369,
            "epssPercentile": 0.70063,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24066",
            "title": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00698,
            "epssPercentile": 0.50755,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24067",
            "title": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00698,
            "epssPercentile": 0.50755,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24071",
            "title": "Microsoft Windows File Explorer Spoofing Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.24638,
            "epssPercentile": 0.97736,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Mitigation available",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "Medium technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24072",
            "title": "Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24984",
            "title": "Microsoft Windows NTFS Information Disclosure Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulnerability that allows an unauthorized attacker to disclose information with a physical attack. An attacker who successfully exploited this vulnerability could potentially read portions of heap memory.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01956,
            "epssPercentile": 0.78953,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24985",
            "title": "Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability",
            "summary": "Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.03846,
            "epssPercentile": 0.89435,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24987",
            "title": "Windows USB Video Class System Driver Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49653,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24988",
            "title": "Windows USB Video Class System Driver Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49653,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24991",
            "title": "Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01979,
            "epssPercentile": 0.79196,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24992",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01047,
            "epssPercentile": 0.61952,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24993",
            "title": "Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02173,
            "epssPercentile": 0.81117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24995",
            "title": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00572,
            "epssPercentile": 0.4517,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24996",
            "title": "NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01292,
            "epssPercentile": 0.68377,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-25008",
            "title": "Windows Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Microsoft Windows allows an authorized attacker to elevate privileges locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.006,
            "epssPercentile": 0.46563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-26633",
            "title": "Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability",
            "summary": "Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11. Known ransomware campaign use is recorded.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.30391,
            "epssPercentile": 0.98108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-26645",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03377,
            "epssPercentile": 0.87972,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-windows-kb5053598",
      "slug": "microsoft-2025-03-windows-kb5053598",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5053598",
      "title": "Deploy Microsoft Windows security update KB5053598",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5053598",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, plus 1 more",
      "platform": "Windows",
      "release_version": "10.0.26100.3476",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-26645",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, plus 1 more exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 35 linked CVEs for Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, plus 1 more. Microsoft reports exploitation for CVE-2025-24984, CVE-2025-24985, CVE-2025-24991, CVE-2025-24993, CVE-2025-26633.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 35,
        "ids": [
          "CVE-2025-21180",
          "CVE-2025-21247",
          "CVE-2025-24035",
          "CVE-2025-24044",
          "CVE-2025-24045",
          "CVE-2025-24046",
          "CVE-2025-24048",
          "CVE-2025-24050",
          "CVE-2025-24051",
          "CVE-2025-24054",
          "CVE-2025-24055",
          "CVE-2025-24056",
          "CVE-2025-24059",
          "CVE-2025-24061",
          "CVE-2025-24064",
          "CVE-2025-24066",
          "CVE-2025-24067",
          "CVE-2025-24071",
          "CVE-2025-24072",
          "CVE-2025-24076",
          "CVE-2025-24084",
          "CVE-2025-24984",
          "CVE-2025-24985",
          "CVE-2025-24987",
          "CVE-2025-24988",
          "CVE-2025-24991",
          "CVE-2025-24992",
          "CVE-2025-24993",
          "CVE-2025-24994",
          "CVE-2025-24995",
          "CVE-2025-24996",
          "CVE-2025-24997",
          "CVE-2025-25008",
          "CVE-2025-26633",
          "CVE-2025-26645"
        ],
        "details": [
          {
            "id": "CVE-2025-21180",
            "title": "Windows exFAT File System Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows exFAT File System allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58294,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21247",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03238,
            "epssPercentile": 0.87457,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24035",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01825,
            "epssPercentile": 0.77382,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24044",
            "title": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00584,
            "epssPercentile": 0.45776,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24045",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01417,
            "epssPercentile": 0.71019,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24046",
            "title": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24048",
            "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43118,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24050",
            "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24051",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01578,
            "epssPercentile": 0.73854,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24054",
            "title": "Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-04-17.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.58909,
            "epssPercentile": 0.99044,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Mitigation available",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-05-08 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24055",
            "title": "Windows USB Video Class System Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to disclose information with a physical attack.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00854,
            "epssPercentile": 0.55945,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24056",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Server allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01673,
            "epssPercentile": 0.75274,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24059",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Incorrect conversion between numeric types in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43118,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24061",
            "title": "Windows Mark of the Web Security Feature Bypass Vulnerability",
            "summary": "Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01183,
            "epssPercentile": 0.65719,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24064",
            "title": "Windows Domain Name Service Remote Code Execution Vulnerability",
            "summary": "Use after free in DNS Server allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01369,
            "epssPercentile": 0.70063,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24066",
            "title": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00698,
            "epssPercentile": 0.50755,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24067",
            "title": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00698,
            "epssPercentile": 0.50755,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24071",
            "title": "Microsoft Windows File Explorer Spoofing Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.24638,
            "epssPercentile": 0.97736,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Mitigation available",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "Medium technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24072",
            "title": "Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24076",
            "title": "Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03151,
            "epssPercentile": 0.87092,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24084",
            "title": "Windows Subsystem for Linux (WSL2) Kernel Remote Code Execution Vulnerability",
            "summary": "Untrusted pointer dereference in Windows Subsystem for Linux allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00684,
            "epssPercentile": 0.50268,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24984",
            "title": "Microsoft Windows NTFS Information Disclosure Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulnerability that allows an unauthorized attacker to disclose information with a physical attack. An attacker who successfully exploited this vulnerability could potentially read portions of heap memory.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01956,
            "epssPercentile": 0.78953,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24985",
            "title": "Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability",
            "summary": "Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.03846,
            "epssPercentile": 0.89435,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24987",
            "title": "Windows USB Video Class System Driver Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49653,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24988",
            "title": "Windows USB Video Class System Driver Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49653,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24991",
            "title": "Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01979,
            "epssPercentile": 0.79196,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24992",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01047,
            "epssPercentile": 0.61952,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24993",
            "title": "Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02173,
            "epssPercentile": 0.81117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24994",
            "title": "Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01166,
            "epssPercentile": 0.6525,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24995",
            "title": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00572,
            "epssPercentile": 0.4517,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24996",
            "title": "NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01292,
            "epssPercentile": 0.68377,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24997",
            "title": "DirectX Graphics Kernel File Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows Kernel Memory allows an authorized attacker to deny service locally.",
            "score": 4.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00593,
            "epssPercentile": 0.46191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-25008",
            "title": "Windows Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Microsoft Windows allows an authorized attacker to elevate privileges locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.006,
            "epssPercentile": 0.46563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-26633",
            "title": "Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability",
            "summary": "Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11. Known ransomware campaign use is recorded.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.30391,
            "epssPercentile": 0.98108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-26645",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03377,
            "epssPercentile": 0.87972,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-windows-kb5053599",
      "slug": "microsoft-2025-03-windows-kb5053599",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5053599",
      "title": "Deploy Microsoft Windows security update KB5053599",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5053599",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Windows Server 2022, 23H2 Edition (Server Core installation)",
      "platform": "Windows",
      "release_version": "10.0.25398.1486",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-26645",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows Server 2022, 23H2 Edition (Server Core installation) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 34 linked CVEs for Windows Server 2022, 23H2 Edition (Server Core installation). Microsoft reports exploitation for CVE-2025-24984, CVE-2025-24985, CVE-2025-24991, CVE-2025-24993, CVE-2025-26633.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 34,
        "ids": [
          "CVE-2025-21180",
          "CVE-2025-21247",
          "CVE-2025-24035",
          "CVE-2025-24044",
          "CVE-2025-24045",
          "CVE-2025-24046",
          "CVE-2025-24048",
          "CVE-2025-24050",
          "CVE-2025-24051",
          "CVE-2025-24054",
          "CVE-2025-24055",
          "CVE-2025-24056",
          "CVE-2025-24059",
          "CVE-2025-24061",
          "CVE-2025-24064",
          "CVE-2025-24066",
          "CVE-2025-24067",
          "CVE-2025-24071",
          "CVE-2025-24072",
          "CVE-2025-24076",
          "CVE-2025-24084",
          "CVE-2025-24984",
          "CVE-2025-24985",
          "CVE-2025-24987",
          "CVE-2025-24988",
          "CVE-2025-24991",
          "CVE-2025-24992",
          "CVE-2025-24993",
          "CVE-2025-24995",
          "CVE-2025-24996",
          "CVE-2025-24997",
          "CVE-2025-25008",
          "CVE-2025-26633",
          "CVE-2025-26645"
        ],
        "details": [
          {
            "id": "CVE-2025-21180",
            "title": "Windows exFAT File System Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows exFAT File System allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58294,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21247",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03238,
            "epssPercentile": 0.87457,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24035",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01825,
            "epssPercentile": 0.77382,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24044",
            "title": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00584,
            "epssPercentile": 0.45776,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24045",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01417,
            "epssPercentile": 0.71019,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24046",
            "title": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24048",
            "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43118,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24050",
            "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24051",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01578,
            "epssPercentile": 0.73854,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24054",
            "title": "Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-04-17.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.58909,
            "epssPercentile": 0.99044,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Mitigation available",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-05-08 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24055",
            "title": "Windows USB Video Class System Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to disclose information with a physical attack.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00854,
            "epssPercentile": 0.55945,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24056",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Server allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01673,
            "epssPercentile": 0.75274,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24059",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Incorrect conversion between numeric types in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43118,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24061",
            "title": "Windows Mark of the Web Security Feature Bypass Vulnerability",
            "summary": "Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01183,
            "epssPercentile": 0.65719,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24064",
            "title": "Windows Domain Name Service Remote Code Execution Vulnerability",
            "summary": "Use after free in DNS Server allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01369,
            "epssPercentile": 0.70063,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24066",
            "title": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00698,
            "epssPercentile": 0.50755,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24067",
            "title": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00698,
            "epssPercentile": 0.50755,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24071",
            "title": "Microsoft Windows File Explorer Spoofing Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.24638,
            "epssPercentile": 0.97736,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Mitigation available",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "Medium technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24072",
            "title": "Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24076",
            "title": "Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03151,
            "epssPercentile": 0.87092,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24084",
            "title": "Windows Subsystem for Linux (WSL2) Kernel Remote Code Execution Vulnerability",
            "summary": "Untrusted pointer dereference in Windows Subsystem for Linux allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00684,
            "epssPercentile": 0.50268,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24984",
            "title": "Microsoft Windows NTFS Information Disclosure Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulnerability that allows an unauthorized attacker to disclose information with a physical attack. An attacker who successfully exploited this vulnerability could potentially read portions of heap memory.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01956,
            "epssPercentile": 0.78953,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24985",
            "title": "Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability",
            "summary": "Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.03846,
            "epssPercentile": 0.89435,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24987",
            "title": "Windows USB Video Class System Driver Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49653,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24988",
            "title": "Windows USB Video Class System Driver Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49653,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24991",
            "title": "Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01979,
            "epssPercentile": 0.79196,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24992",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01047,
            "epssPercentile": 0.61952,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24993",
            "title": "Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02173,
            "epssPercentile": 0.81117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24995",
            "title": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00572,
            "epssPercentile": 0.4517,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24996",
            "title": "NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01292,
            "epssPercentile": 0.68377,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24997",
            "title": "DirectX Graphics Kernel File Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows Kernel Memory allows an authorized attacker to deny service locally.",
            "score": 4.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00593,
            "epssPercentile": 0.46191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-25008",
            "title": "Windows Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Microsoft Windows allows an authorized attacker to elevate privileges locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.006,
            "epssPercentile": 0.46563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-26633",
            "title": "Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability",
            "summary": "Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11. Known ransomware campaign use is recorded.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.30391,
            "epssPercentile": 0.98108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-26645",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03377,
            "epssPercentile": 0.87972,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-windows-kb5053602",
      "slug": "microsoft-2025-03-windows-kb5053602",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5053602",
      "title": "Deploy Microsoft Windows security update KB5053602",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5053602",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Windows 11 Version 23H2 for ARM64-based Systems, Windows 11 Version 23H2 for x64-based Systems",
      "platform": "Windows",
      "release_version": "10.0.22631.5039",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-26645",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows 11 Version 23H2 for ARM64-based Systems, Windows 11 Version 23H2 for x64-based Systems exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 32 linked CVEs for Windows 11 Version 23H2 for ARM64-based Systems, Windows 11 Version 23H2 for x64-based Systems. Microsoft reports exploitation for CVE-2025-24984, CVE-2025-24985, CVE-2025-24991, CVE-2025-24993, CVE-2025-26633.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 32,
        "ids": [
          "CVE-2025-21180",
          "CVE-2025-21247",
          "CVE-2025-24035",
          "CVE-2025-24044",
          "CVE-2025-24046",
          "CVE-2025-24048",
          "CVE-2025-24050",
          "CVE-2025-24051",
          "CVE-2025-24054",
          "CVE-2025-24055",
          "CVE-2025-24056",
          "CVE-2025-24059",
          "CVE-2025-24061",
          "CVE-2025-24066",
          "CVE-2025-24067",
          "CVE-2025-24071",
          "CVE-2025-24072",
          "CVE-2025-24076",
          "CVE-2025-24084",
          "CVE-2025-24984",
          "CVE-2025-24985",
          "CVE-2025-24987",
          "CVE-2025-24988",
          "CVE-2025-24991",
          "CVE-2025-24992",
          "CVE-2025-24993",
          "CVE-2025-24994",
          "CVE-2025-24995",
          "CVE-2025-24996",
          "CVE-2025-24997",
          "CVE-2025-26633",
          "CVE-2025-26645"
        ],
        "details": [
          {
            "id": "CVE-2025-21180",
            "title": "Windows exFAT File System Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows exFAT File System allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58294,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21247",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03238,
            "epssPercentile": 0.87457,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24035",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01825,
            "epssPercentile": 0.77382,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24044",
            "title": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00584,
            "epssPercentile": 0.45776,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24046",
            "title": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24048",
            "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43118,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24050",
            "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24051",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01578,
            "epssPercentile": 0.73854,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24054",
            "title": "Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-04-17.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.58909,
            "epssPercentile": 0.99044,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Mitigation available",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-05-08 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24055",
            "title": "Windows USB Video Class System Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to disclose information with a physical attack.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00854,
            "epssPercentile": 0.55945,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24056",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Server allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01673,
            "epssPercentile": 0.75274,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24059",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Incorrect conversion between numeric types in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43118,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24061",
            "title": "Windows Mark of the Web Security Feature Bypass Vulnerability",
            "summary": "Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01183,
            "epssPercentile": 0.65719,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24066",
            "title": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00698,
            "epssPercentile": 0.50755,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24067",
            "title": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00698,
            "epssPercentile": 0.50755,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24071",
            "title": "Microsoft Windows File Explorer Spoofing Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.24638,
            "epssPercentile": 0.97736,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Mitigation available",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "Medium technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24072",
            "title": "Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24076",
            "title": "Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03151,
            "epssPercentile": 0.87092,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24084",
            "title": "Windows Subsystem for Linux (WSL2) Kernel Remote Code Execution Vulnerability",
            "summary": "Untrusted pointer dereference in Windows Subsystem for Linux allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00684,
            "epssPercentile": 0.50268,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24984",
            "title": "Microsoft Windows NTFS Information Disclosure Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulnerability that allows an unauthorized attacker to disclose information with a physical attack. An attacker who successfully exploited this vulnerability could potentially read portions of heap memory.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01956,
            "epssPercentile": 0.78953,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24985",
            "title": "Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability",
            "summary": "Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.03846,
            "epssPercentile": 0.89435,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24987",
            "title": "Windows USB Video Class System Driver Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49653,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24988",
            "title": "Windows USB Video Class System Driver Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49653,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24991",
            "title": "Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01979,
            "epssPercentile": 0.79196,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24992",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01047,
            "epssPercentile": 0.61952,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24993",
            "title": "Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02173,
            "epssPercentile": 0.81117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24994",
            "title": "Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01166,
            "epssPercentile": 0.6525,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24995",
            "title": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00572,
            "epssPercentile": 0.4517,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24996",
            "title": "NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01292,
            "epssPercentile": 0.68377,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24997",
            "title": "DirectX Graphics Kernel File Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows Kernel Memory allows an authorized attacker to deny service locally.",
            "score": 4.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00593,
            "epssPercentile": 0.46191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-26633",
            "title": "Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability",
            "summary": "Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11. Known ransomware campaign use is recorded.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.30391,
            "epssPercentile": 0.98108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-26645",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03377,
            "epssPercentile": 0.87972,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-windows-kb5053603",
      "slug": "microsoft-2025-03-windows-kb5053603",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5053603",
      "title": "Deploy Microsoft Windows security update KB5053603",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5053603",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Windows Server 2022, Windows Server 2022 (Server Core installation)",
      "platform": "Windows",
      "release_version": "10.0.20348.3328",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-26645",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows Server 2022, Windows Server 2022 (Server Core installation) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 33 linked CVEs for Windows Server 2022, Windows Server 2022 (Server Core installation). Microsoft reports exploitation for CVE-2025-24984, CVE-2025-24985, CVE-2025-24991, CVE-2025-24993, CVE-2025-26633.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 33,
        "ids": [
          "CVE-2025-21180",
          "CVE-2025-21247",
          "CVE-2025-24035",
          "CVE-2025-24044",
          "CVE-2025-24045",
          "CVE-2025-24046",
          "CVE-2025-24048",
          "CVE-2025-24050",
          "CVE-2025-24051",
          "CVE-2025-24054",
          "CVE-2025-24055",
          "CVE-2025-24056",
          "CVE-2025-24059",
          "CVE-2025-24061",
          "CVE-2025-24064",
          "CVE-2025-24066",
          "CVE-2025-24067",
          "CVE-2025-24071",
          "CVE-2025-24072",
          "CVE-2025-24084",
          "CVE-2025-24984",
          "CVE-2025-24985",
          "CVE-2025-24987",
          "CVE-2025-24988",
          "CVE-2025-24991",
          "CVE-2025-24992",
          "CVE-2025-24993",
          "CVE-2025-24995",
          "CVE-2025-24996",
          "CVE-2025-24997",
          "CVE-2025-25008",
          "CVE-2025-26633",
          "CVE-2025-26645"
        ],
        "details": [
          {
            "id": "CVE-2025-21180",
            "title": "Windows exFAT File System Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows exFAT File System allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58294,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21247",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03238,
            "epssPercentile": 0.87457,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24035",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01825,
            "epssPercentile": 0.77382,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24044",
            "title": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00584,
            "epssPercentile": 0.45776,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24045",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01417,
            "epssPercentile": 0.71019,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24046",
            "title": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24048",
            "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43118,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24050",
            "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24051",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01578,
            "epssPercentile": 0.73854,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24054",
            "title": "Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-04-17.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.58909,
            "epssPercentile": 0.99044,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Mitigation available",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-05-08 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24055",
            "title": "Windows USB Video Class System Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to disclose information with a physical attack.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00854,
            "epssPercentile": 0.55945,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24056",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Server allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01673,
            "epssPercentile": 0.75274,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24059",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Incorrect conversion between numeric types in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43118,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24061",
            "title": "Windows Mark of the Web Security Feature Bypass Vulnerability",
            "summary": "Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01183,
            "epssPercentile": 0.65719,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24064",
            "title": "Windows Domain Name Service Remote Code Execution Vulnerability",
            "summary": "Use after free in DNS Server allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01369,
            "epssPercentile": 0.70063,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24066",
            "title": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00698,
            "epssPercentile": 0.50755,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24067",
            "title": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00698,
            "epssPercentile": 0.50755,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24071",
            "title": "Microsoft Windows File Explorer Spoofing Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.24638,
            "epssPercentile": 0.97736,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Mitigation available",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "Medium technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24072",
            "title": "Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24084",
            "title": "Windows Subsystem for Linux (WSL2) Kernel Remote Code Execution Vulnerability",
            "summary": "Untrusted pointer dereference in Windows Subsystem for Linux allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00684,
            "epssPercentile": 0.50268,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24984",
            "title": "Microsoft Windows NTFS Information Disclosure Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulnerability that allows an unauthorized attacker to disclose information with a physical attack. An attacker who successfully exploited this vulnerability could potentially read portions of heap memory.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01956,
            "epssPercentile": 0.78953,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24985",
            "title": "Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability",
            "summary": "Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.03846,
            "epssPercentile": 0.89435,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24987",
            "title": "Windows USB Video Class System Driver Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49653,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24988",
            "title": "Windows USB Video Class System Driver Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49653,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24991",
            "title": "Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01979,
            "epssPercentile": 0.79196,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24992",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01047,
            "epssPercentile": 0.61952,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24993",
            "title": "Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02173,
            "epssPercentile": 0.81117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24995",
            "title": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00572,
            "epssPercentile": 0.4517,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24996",
            "title": "NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01292,
            "epssPercentile": 0.68377,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24997",
            "title": "DirectX Graphics Kernel File Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows Kernel Memory allows an authorized attacker to deny service locally.",
            "score": 4.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00593,
            "epssPercentile": 0.46191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-25008",
            "title": "Windows Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Microsoft Windows allows an authorized attacker to elevate privileges locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.006,
            "epssPercentile": 0.46563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-26633",
            "title": "Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability",
            "summary": "Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11. Known ransomware campaign use is recorded.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.30391,
            "epssPercentile": 0.98108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-26645",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03377,
            "epssPercentile": 0.87972,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-windows-kb5053606",
      "slug": "microsoft-2025-03-windows-kb5053606",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5053606",
      "title": "Deploy Microsoft Windows security update KB5053606",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5053606",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems",
      "platform": "Windows",
      "release_version": "10.0.19044.5608",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-26645",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 29 linked CVEs for Windows 10 Version 21H2 for 32-bit Systems, Windows 10 Version 21H2 for ARM64-based Systems, Windows 10 Version 21H2 for x64-based Systems. Microsoft reports exploitation for CVE-2025-24984, CVE-2025-24985, CVE-2025-24991, CVE-2025-24993, CVE-2025-26633.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 29,
        "ids": [
          "CVE-2025-21180",
          "CVE-2025-21247",
          "CVE-2025-24035",
          "CVE-2025-24044",
          "CVE-2025-24046",
          "CVE-2025-24048",
          "CVE-2025-24050",
          "CVE-2025-24051",
          "CVE-2025-24054",
          "CVE-2025-24055",
          "CVE-2025-24056",
          "CVE-2025-24059",
          "CVE-2025-24061",
          "CVE-2025-24066",
          "CVE-2025-24067",
          "CVE-2025-24071",
          "CVE-2025-24072",
          "CVE-2025-24984",
          "CVE-2025-24985",
          "CVE-2025-24987",
          "CVE-2025-24988",
          "CVE-2025-24991",
          "CVE-2025-24992",
          "CVE-2025-24993",
          "CVE-2025-24995",
          "CVE-2025-24996",
          "CVE-2025-24997",
          "CVE-2025-26633",
          "CVE-2025-26645"
        ],
        "details": [
          {
            "id": "CVE-2025-21180",
            "title": "Windows exFAT File System Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows exFAT File System allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58294,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21247",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03238,
            "epssPercentile": 0.87457,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24035",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01825,
            "epssPercentile": 0.77382,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24044",
            "title": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00584,
            "epssPercentile": 0.45776,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24046",
            "title": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24048",
            "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43118,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24050",
            "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24051",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01578,
            "epssPercentile": 0.73854,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24054",
            "title": "Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-04-17.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.58909,
            "epssPercentile": 0.99044,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Mitigation available",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-05-08 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24055",
            "title": "Windows USB Video Class System Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to disclose information with a physical attack.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00854,
            "epssPercentile": 0.55945,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24056",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Server allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01673,
            "epssPercentile": 0.75274,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24059",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Incorrect conversion between numeric types in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43118,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24061",
            "title": "Windows Mark of the Web Security Feature Bypass Vulnerability",
            "summary": "Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01183,
            "epssPercentile": 0.65719,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24066",
            "title": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00698,
            "epssPercentile": 0.50755,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24067",
            "title": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00698,
            "epssPercentile": 0.50755,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24071",
            "title": "Microsoft Windows File Explorer Spoofing Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.24638,
            "epssPercentile": 0.97736,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Mitigation available",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "Medium technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24072",
            "title": "Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24984",
            "title": "Microsoft Windows NTFS Information Disclosure Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulnerability that allows an unauthorized attacker to disclose information with a physical attack. An attacker who successfully exploited this vulnerability could potentially read portions of heap memory.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01956,
            "epssPercentile": 0.78953,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24985",
            "title": "Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability",
            "summary": "Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.03846,
            "epssPercentile": 0.89435,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24987",
            "title": "Windows USB Video Class System Driver Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49653,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24988",
            "title": "Windows USB Video Class System Driver Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49653,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24991",
            "title": "Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01979,
            "epssPercentile": 0.79196,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24992",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01047,
            "epssPercentile": 0.61952,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24993",
            "title": "Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02173,
            "epssPercentile": 0.81117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24995",
            "title": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00572,
            "epssPercentile": 0.4517,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24996",
            "title": "NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01292,
            "epssPercentile": 0.68377,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24997",
            "title": "DirectX Graphics Kernel File Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows Kernel Memory allows an authorized attacker to deny service locally.",
            "score": 4.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00593,
            "epssPercentile": 0.46191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-26633",
            "title": "Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability",
            "summary": "Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11. Known ransomware campaign use is recorded.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.30391,
            "epssPercentile": 0.98108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-26645",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03377,
            "epssPercentile": 0.87972,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-windows-kb5053618",
      "slug": "microsoft-2025-03-windows-kb5053618",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5053618",
      "title": "Deploy Microsoft Windows security update KB5053618",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5053618",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Windows 10 for 32-bit Systems, Windows 10 for x64-based Systems",
      "platform": "Windows",
      "release_version": "10.0.10240.20947",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-26645",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows 10 for 32-bit Systems, Windows 10 for x64-based Systems exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 27 linked CVEs for Windows 10 for 32-bit Systems, Windows 10 for x64-based Systems. Microsoft reports exploitation for CVE-2025-24983, CVE-2025-24984, CVE-2025-24985, CVE-2025-24991, CVE-2025-24993, CVE-2025-26633.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 27,
        "ids": [
          "CVE-2025-21180",
          "CVE-2025-21247",
          "CVE-2025-24035",
          "CVE-2025-24044",
          "CVE-2025-24046",
          "CVE-2025-24051",
          "CVE-2025-24054",
          "CVE-2025-24055",
          "CVE-2025-24056",
          "CVE-2025-24059",
          "CVE-2025-24061",
          "CVE-2025-24066",
          "CVE-2025-24067",
          "CVE-2025-24071",
          "CVE-2025-24072",
          "CVE-2025-24983",
          "CVE-2025-24984",
          "CVE-2025-24985",
          "CVE-2025-24987",
          "CVE-2025-24988",
          "CVE-2025-24991",
          "CVE-2025-24992",
          "CVE-2025-24993",
          "CVE-2025-24995",
          "CVE-2025-24996",
          "CVE-2025-26633",
          "CVE-2025-26645"
        ],
        "details": [
          {
            "id": "CVE-2025-21180",
            "title": "Windows exFAT File System Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows exFAT File System allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58294,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21247",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03238,
            "epssPercentile": 0.87457,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24035",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01825,
            "epssPercentile": 0.77382,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24044",
            "title": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00584,
            "epssPercentile": 0.45776,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24046",
            "title": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24051",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01578,
            "epssPercentile": 0.73854,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24054",
            "title": "Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-04-17.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.58909,
            "epssPercentile": 0.99044,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Mitigation available",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-05-08 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24055",
            "title": "Windows USB Video Class System Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to disclose information with a physical attack.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00854,
            "epssPercentile": 0.55945,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24056",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Server allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01673,
            "epssPercentile": 0.75274,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24059",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Incorrect conversion between numeric types in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43118,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24061",
            "title": "Windows Mark of the Web Security Feature Bypass Vulnerability",
            "summary": "Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01183,
            "epssPercentile": 0.65719,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24066",
            "title": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00698,
            "epssPercentile": 0.50755,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24067",
            "title": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00698,
            "epssPercentile": 0.50755,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24071",
            "title": "Microsoft Windows File Explorer Spoofing Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.24638,
            "epssPercentile": 0.97736,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Mitigation available",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "Medium technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24072",
            "title": "Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24983",
            "title": "Microsoft Windows Win32k Use-After-Free Vulnerability",
            "summary": "Microsoft Windows Win32 Kernel Subsystem contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01348,
            "epssPercentile": 0.69617,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24984",
            "title": "Microsoft Windows NTFS Information Disclosure Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulnerability that allows an unauthorized attacker to disclose information with a physical attack. An attacker who successfully exploited this vulnerability could potentially read portions of heap memory.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01956,
            "epssPercentile": 0.78953,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24985",
            "title": "Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability",
            "summary": "Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.03846,
            "epssPercentile": 0.89435,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24987",
            "title": "Windows USB Video Class System Driver Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49653,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24988",
            "title": "Windows USB Video Class System Driver Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49653,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24991",
            "title": "Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01979,
            "epssPercentile": 0.79196,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24992",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01047,
            "epssPercentile": 0.61952,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24993",
            "title": "Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02173,
            "epssPercentile": 0.81117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24995",
            "title": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00572,
            "epssPercentile": 0.4517,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24996",
            "title": "NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01292,
            "epssPercentile": 0.68377,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-26633",
            "title": "Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability",
            "summary": "Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11. Known ransomware campaign use is recorded.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.30391,
            "epssPercentile": 0.98108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-26645",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03377,
            "epssPercentile": 0.87972,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-windows-kb5053636",
      "slug": "microsoft-2025-03-windows-kb5053636",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5053636",
      "title": "Deploy Microsoft Windows security update KB5053636",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5053636",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, plus 1 more",
      "platform": "Windows",
      "release_version": "10.0.26100.3403",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-26645",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, plus 1 more exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 35 linked CVEs for Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows Server 2025, plus 1 more. Microsoft reports exploitation for CVE-2025-24984, CVE-2025-24985, CVE-2025-24991, CVE-2025-24993, CVE-2025-26633.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 35,
        "ids": [
          "CVE-2025-21180",
          "CVE-2025-21247",
          "CVE-2025-24035",
          "CVE-2025-24044",
          "CVE-2025-24045",
          "CVE-2025-24046",
          "CVE-2025-24048",
          "CVE-2025-24050",
          "CVE-2025-24051",
          "CVE-2025-24054",
          "CVE-2025-24055",
          "CVE-2025-24056",
          "CVE-2025-24059",
          "CVE-2025-24061",
          "CVE-2025-24064",
          "CVE-2025-24066",
          "CVE-2025-24067",
          "CVE-2025-24071",
          "CVE-2025-24072",
          "CVE-2025-24076",
          "CVE-2025-24084",
          "CVE-2025-24984",
          "CVE-2025-24985",
          "CVE-2025-24987",
          "CVE-2025-24988",
          "CVE-2025-24991",
          "CVE-2025-24992",
          "CVE-2025-24993",
          "CVE-2025-24994",
          "CVE-2025-24995",
          "CVE-2025-24996",
          "CVE-2025-24997",
          "CVE-2025-25008",
          "CVE-2025-26633",
          "CVE-2025-26645"
        ],
        "details": [
          {
            "id": "CVE-2025-21180",
            "title": "Windows exFAT File System Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows exFAT File System allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58294,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21247",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03238,
            "epssPercentile": 0.87457,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24035",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01825,
            "epssPercentile": 0.77382,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24044",
            "title": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00584,
            "epssPercentile": 0.45776,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24045",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01417,
            "epssPercentile": 0.71019,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24046",
            "title": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24048",
            "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43118,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24050",
            "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24051",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01578,
            "epssPercentile": 0.73854,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24054",
            "title": "Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-04-17.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.58909,
            "epssPercentile": 0.99044,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Mitigation available",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-05-08 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24055",
            "title": "Windows USB Video Class System Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to disclose information with a physical attack.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00854,
            "epssPercentile": 0.55945,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24056",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Server allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01673,
            "epssPercentile": 0.75274,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24059",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Incorrect conversion between numeric types in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43118,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24061",
            "title": "Windows Mark of the Web Security Feature Bypass Vulnerability",
            "summary": "Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01183,
            "epssPercentile": 0.65719,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24064",
            "title": "Windows Domain Name Service Remote Code Execution Vulnerability",
            "summary": "Use after free in DNS Server allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01369,
            "epssPercentile": 0.70063,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24066",
            "title": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00698,
            "epssPercentile": 0.50755,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24067",
            "title": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00698,
            "epssPercentile": 0.50755,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24071",
            "title": "Microsoft Windows File Explorer Spoofing Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.24638,
            "epssPercentile": 0.97736,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Mitigation available",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "Medium technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24072",
            "title": "Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24076",
            "title": "Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03151,
            "epssPercentile": 0.87092,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24084",
            "title": "Windows Subsystem for Linux (WSL2) Kernel Remote Code Execution Vulnerability",
            "summary": "Untrusted pointer dereference in Windows Subsystem for Linux allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00684,
            "epssPercentile": 0.50268,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24984",
            "title": "Microsoft Windows NTFS Information Disclosure Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulnerability that allows an unauthorized attacker to disclose information with a physical attack. An attacker who successfully exploited this vulnerability could potentially read portions of heap memory.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01956,
            "epssPercentile": 0.78953,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24985",
            "title": "Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability",
            "summary": "Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.03846,
            "epssPercentile": 0.89435,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24987",
            "title": "Windows USB Video Class System Driver Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49653,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24988",
            "title": "Windows USB Video Class System Driver Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49653,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24991",
            "title": "Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01979,
            "epssPercentile": 0.79196,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24992",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01047,
            "epssPercentile": 0.61952,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24993",
            "title": "Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02173,
            "epssPercentile": 0.81117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24994",
            "title": "Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability",
            "summary": "Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.3,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01166,
            "epssPercentile": 0.6525,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24995",
            "title": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00572,
            "epssPercentile": 0.4517,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24996",
            "title": "NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01292,
            "epssPercentile": 0.68377,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24997",
            "title": "DirectX Graphics Kernel File Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows Kernel Memory allows an authorized attacker to deny service locally.",
            "score": 4.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00593,
            "epssPercentile": 0.46191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-25008",
            "title": "Windows Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Microsoft Windows allows an authorized attacker to elevate privileges locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.006,
            "epssPercentile": 0.46563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-26633",
            "title": "Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability",
            "summary": "Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11. Known ransomware campaign use is recorded.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.30391,
            "epssPercentile": 0.98108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-26645",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03377,
            "epssPercentile": 0.87972,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-windows-kb5053638",
      "slug": "microsoft-2025-03-windows-kb5053638",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "KB5053638",
      "title": "Deploy Microsoft Windows security update KB5053638",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://support.microsoft.com/help/5053638",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Windows Server 2022, Windows Server 2022 (Server Core installation)",
      "platform": "Windows",
      "release_version": "10.0.20348.3270",
      "action_type": "deploy-patch",
      "restart_required": "yes",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "confirmed",
        "vendor_exploitability": "Microsoft reports exploitation",
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-26645",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "A restart is required. Plan service interruption and validation.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows Server 2022, Windows Server 2022 (Server Core installation) exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "patch-now",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ACTIVE_EXPLOITATION_CONFIRMED"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 33 linked CVEs for Windows Server 2022, Windows Server 2022 (Server Core installation). Microsoft reports exploitation for CVE-2025-24984, CVE-2025-24985, CVE-2025-24991, CVE-2025-24993, CVE-2025-26633.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 33,
        "ids": [
          "CVE-2025-21180",
          "CVE-2025-21247",
          "CVE-2025-24035",
          "CVE-2025-24044",
          "CVE-2025-24045",
          "CVE-2025-24046",
          "CVE-2025-24048",
          "CVE-2025-24050",
          "CVE-2025-24051",
          "CVE-2025-24054",
          "CVE-2025-24055",
          "CVE-2025-24056",
          "CVE-2025-24059",
          "CVE-2025-24061",
          "CVE-2025-24064",
          "CVE-2025-24066",
          "CVE-2025-24067",
          "CVE-2025-24071",
          "CVE-2025-24072",
          "CVE-2025-24084",
          "CVE-2025-24984",
          "CVE-2025-24985",
          "CVE-2025-24987",
          "CVE-2025-24988",
          "CVE-2025-24991",
          "CVE-2025-24992",
          "CVE-2025-24993",
          "CVE-2025-24995",
          "CVE-2025-24996",
          "CVE-2025-24997",
          "CVE-2025-25008",
          "CVE-2025-26633",
          "CVE-2025-26645"
        ],
        "details": [
          {
            "id": "CVE-2025-21180",
            "title": "Windows exFAT File System Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows exFAT File System allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0093,
            "epssPercentile": 0.58294,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-21247",
            "title": "MapUrlToZone Security Feature Bypass Vulnerability",
            "summary": "Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03238,
            "epssPercentile": 0.87457,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24035",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01825,
            "epssPercentile": 0.77382,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24044",
            "title": "Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability",
            "summary": "Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00584,
            "epssPercentile": 0.45776,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24045",
            "title": "Windows Remote Desktop Services Remote Code Execution Vulnerability",
            "summary": "Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01417,
            "epssPercentile": 0.71019,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24046",
            "title": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24048",
            "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43118,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24050",
            "title": "Windows Hyper-V Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24051",
            "title": "Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01578,
            "epssPercentile": 0.73854,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24054",
            "title": "Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-04-17.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.58909,
            "epssPercentile": 0.99044,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Mitigation available",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-05-08 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24055",
            "title": "Windows USB Video Class System Driver Information Disclosure Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to disclose information with a physical attack.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00854,
            "epssPercentile": 0.55945,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24056",
            "title": "Windows Telephony Service Remote Code Execution Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Telephony Server allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01673,
            "epssPercentile": 0.75274,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24059",
            "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
            "summary": "Incorrect conversion between numeric types in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43118,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24061",
            "title": "Windows Mark of the Web Security Feature Bypass Vulnerability",
            "summary": "Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01183,
            "epssPercentile": 0.65719,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24064",
            "title": "Windows Domain Name Service Remote Code Execution Vulnerability",
            "summary": "Use after free in DNS Server allows an unauthorized attacker to execute code over a network.",
            "score": 8.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01369,
            "epssPercentile": 0.70063,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24066",
            "title": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00698,
            "epssPercentile": 0.50755,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24067",
            "title": "Kernel Streaming Service Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00698,
            "epssPercentile": 0.50755,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24071",
            "title": "Microsoft Windows File Explorer Spoofing Vulnerability",
            "summary": "Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.24638,
            "epssPercentile": 0.97736,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Mitigation available",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "Medium technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24072",
            "title": "Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability",
            "summary": "Use after free in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00533,
            "epssPercentile": 0.43117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24084",
            "title": "Windows Subsystem for Linux (WSL2) Kernel Remote Code Execution Vulnerability",
            "summary": "Untrusted pointer dereference in Windows Subsystem for Linux allows an unauthorized attacker to execute code locally.",
            "score": 8.4,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00684,
            "epssPercentile": 0.50268,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24984",
            "title": "Microsoft Windows NTFS Information Disclosure Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulnerability that allows an unauthorized attacker to disclose information with a physical attack. An attacker who successfully exploited this vulnerability could potentially read portions of heap memory.",
            "score": 4.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01956,
            "epssPercentile": 0.78953,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24985",
            "title": "Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability",
            "summary": "Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.03846,
            "epssPercentile": 0.89435,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24987",
            "title": "Windows USB Video Class System Driver Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49653,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24988",
            "title": "Windows USB Video Class System Driver Elevation of Privilege Vulnerability",
            "summary": "Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.",
            "score": 6.6,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00669,
            "epssPercentile": 0.49653,
            "epssDate": "2026-09-06",
            "attackVector": "PHYSICAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24991",
            "title": "Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01979,
            "epssPercentile": 0.79196,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24992",
            "title": "Windows NTFS Information Disclosure Vulnerability",
            "summary": "Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.",
            "score": 5.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01047,
            "epssPercentile": 0.61952,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24993",
            "title": "Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability",
            "summary": "Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.02173,
            "epssPercentile": 0.81117,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24995",
            "title": "Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability",
            "summary": "Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally.",
            "score": 7.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00572,
            "epssPercentile": 0.4517,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24996",
            "title": "NTLM Hash Disclosure Spoofing Vulnerability",
            "summary": "External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.",
            "score": 6.5,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.01292,
            "epssPercentile": 0.68377,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-24997",
            "title": "DirectX Graphics Kernel File Denial of Service Vulnerability",
            "summary": "Null pointer dereference in Windows Kernel Memory allows an authorized attacker to deny service locally.",
            "score": 4.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00593,
            "epssPercentile": 0.46191,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-25008",
            "title": "Windows Server Elevation of Privilege Vulnerability",
            "summary": "Improper link resolution before file access ('link following') in Microsoft Windows allows an authorized attacker to elevate privileges locally.",
            "score": 7.1,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.006,
            "epssPercentile": 0.46563,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-26633",
            "title": "Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability",
            "summary": "Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally.",
            "score": 7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": true,
            "wildDetail": "CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-03-11. Known ransomware campaign use is recorded.",
            "publicExploit": "Public exploit reference",
            "publicExploitDetail": "A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.",
            "epss": 0.30391,
            "epssPercentile": 0.98108,
            "epssDate": "2026-09-06",
            "attackVector": "LOCAL",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Patch now",
            "urgencyReason": "CISA confirms exploitation in the wild and lists 2025-04-01 as the remediation due date.",
            "confidence": "High"
          },
          {
            "id": "CVE-2025-26645",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03377,
            "epssPercentile": 0.87972,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-windows-msrc-2025-03-windows-release-notes-windows-app-client-for-windows-desktop",
      "slug": "microsoft-2025-03-windows-msrc-2025-03-windows-release-notes-windows-app-client-for-windows-desktop",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-03-windows-release-notes",
      "title": "Deploy Microsoft Windows update for Windows App Client for Windows Desktop",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://learn.microsoft.com/en-us/windows-app/whats-new?toc=admins%2Ftoc.json&tabs=windows",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Windows App Client for Windows Desktop",
      "platform": "Windows",
      "release_version": "2.0.365.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-26645",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Windows App Client for Windows Desktop exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Windows App Client for Windows Desktop.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-26645"
        ],
        "details": [
          {
            "id": "CVE-2025-26645",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03377,
            "epssPercentile": 0.87972,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "microsoft-2025-03-windows-msrc-2025-03-windows-release-notes-remote-desktop-client-for-windows-desktop",
      "slug": "microsoft-2025-03-windows-msrc-2025-03-windows-release-notes-remote-desktop-client-for-windows-desktop",
      "cycle_id": "2025-03",
      "vendor_id": "microsoft",
      "vendor_name": "Microsoft",
      "source_id": "microsoft-sug",
      "advisory_id": "MSRC-2025-03-windows-release-notes",
      "title": "Deploy Microsoft Windows update for Remote Desktop client for Windows Desktop",
      "source_title": "2025-03 Microsoft Security Update Guide",
      "source_url": "https://learn.microsoft.com/en-us/azure/virtual-desktop/whats-new-client-windows#updates-for-version-1260170",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "Remote Desktop client for Windows Desktop",
      "platform": "Windows",
      "release_version": "1.2.6017.0",
      "action_type": "deploy-patch",
      "restart_required": "varies by product",
      "vendor_severity": "Critical",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 8.8,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-26645",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Test the update in a representative deployment ring before broad release."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "blacktree-generic"
      },
      "environment_questions": [
        "Is Remote Desktop client for Windows Desktop exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "high",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "This official Microsoft Patch Tuesday update addresses 1 linked CVE for Remote Desktop client for Windows Desktop.",
      "cves": {
        "state": "complete-for-update",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-26645"
        ],
        "details": [
          {
            "id": "CVE-2025-26645",
            "title": "Remote Desktop Client Remote Code Execution Vulnerability",
            "summary": "Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.",
            "score": 8.8,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.03377,
            "epssPercentile": 0.87972,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Use the vendor update channel or update catalogue entry for the applicable product release.",
        "Plan a restart when the vendor remediation marks one as required."
      ],
      "data_gaps": [
        "Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.",
        "This update uses vendor release notes or a fixed build instead of a standalone KB identity."
      ],
      "provenance": [
        {
          "field": "patch_identity_and_products",
          "source_path": "msrc-cvrf/vendor-fix",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_exploit_status",
          "source_path": "msrc-cvrf/vulnerability",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Initial Patch Tuesday publication."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The update identity, affected product mapping, restart signal, vendor severity, exploit status and complete CVE relationships were generated from the official MSRC CVRF document and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-03-3347991",
      "slug": "sap-2025-03-3347991",
      "cycle_id": "2025-03",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3347991",
      "title": "Assess and apply SAP security advisory 3347991",
      "source_title": "[CVE-2025-26655] Missing Authorization check in SAP JIT(Outbound) | Product - SAP Just In Time, Version - S4CORE 102, 103, 104, 105, 106, 107, ECC-DIMP 618",
      "source_url": "https://me.sap.com/notes/3347991",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "SAP Just In Time, Version - S4CORE 102, 103, 104, 105, 106, 107, ECC-DIMP 618",
      "platform": "SAP",
      "release_version": "S4CORE 102, 103, 104, 105, 106, 107, ECC-DIMP 618",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Low; CVSS 3.1",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 3.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-26655",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP Just In Time, Version - S4CORE 102, 103, 104, 105, 106, 107, ECC-DIMP 618 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3347991 in its 2025-03 Security Patch Day release for SAP Just In Time, Version - S4CORE 102, 103, 104, 105, 106, 107, ECC-DIMP 618. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-26655"
        ],
        "details": [
          {
            "id": "CVE-2025-26655",
            "title": "Missing Authorization check in SAP JIT(Outbound)",
            "summary": "SAP Just In Time(JIT) does not perform necessary authorization checks for an authenticated user, allowing attacker to escalate privileges that would otherwise be restricted, potentially causing a low impact on the integrity of the application.Confidentiality and Availability are not impacted.",
            "score": 3.1,
            "version": "3.1",
            "severity": "Low",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00214,
            "epssPercentile": 0.11692,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Low technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-03-3474392",
      "slug": "sap-2025-03-3474392",
      "cycle_id": "2025-03",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3474392",
      "title": "Assess and apply SAP security advisory 3474392",
      "source_title": "[CVE-2025-26656] Missing Authorization check in S/4HANA (Manage Purchasing Info Records) | Product - S/4HANA On-Premise, Version - S4CORE 105, 106, 107, 108",
      "source_url": "https://me.sap.com/notes/3474392",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "S/4HANA On-Premise, Version - S4CORE 105, 106, 107, 108",
      "platform": "SAP",
      "release_version": "S4CORE 105, 106, 107, 108",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 4.3",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 4.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-26656",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is S/4HANA On-Premise, Version - S4CORE 105, 106, 107, 108 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3474392 in its 2025-03 Security Patch Day release for S/4HANA On-Premise, Version - S4CORE 105, 106, 107, 108. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-26656"
        ],
        "details": [
          {
            "id": "CVE-2025-26656",
            "title": "Missing Authorization check in S/4HANA (Manage Purchasing Info Records)",
            "summary": "OData Service in Manage Purchasing Info Records does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privileges. This has low impact on integrity of the application.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00235,
            "epssPercentile": 0.14366,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-03-3475427",
      "slug": "sap-2025-03-3475427",
      "cycle_id": "2025-03",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3475427",
      "title": "Assess and apply SAP security advisory 3475427",
      "source_title": "Update to Security Note released on August 2024 Patch Day: [CVE-2024-41736] Information Disclosure vulnerability in SAP Permit to Work | Product - SAP Permit to Work, Versions - UIS4HOP1 800, 900",
      "source_url": "https://me.sap.com/notes/3475427",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "revised",
      "product": "SAP Permit to Work, Versions - UIS4HOP1 800, 900",
      "platform": "SAP",
      "release_version": "s - UIS4HOP1 800, 900",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 4.3",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 4.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2024-41736",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP Permit to Work, Versions - UIS4HOP1 800, 900 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3475427 in its 2025-03 Security Patch Day release for SAP Permit to Work, Versions - UIS4HOP1 800, 900. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2024-41736"
        ],
        "details": [
          {
            "id": "CVE-2024-41736",
            "title": "Information Disclosure vulnerability in SAP Permit to Work",
            "summary": "Under certain conditions SAP Permit to Work allows an authenticated attacker to access information which would otherwise be restricted causing low impact on the confidentiality of the application.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00299,
            "epssPercentile": 0.22212,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-03-3483344",
      "slug": "sap-2025-03-3483344",
      "cycle_id": "2025-03",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3483344",
      "title": "Assess and apply SAP security advisory 3483344",
      "source_title": "Update to Security Note released on July 2024 Patch Day: [CVE-2024-39592] Missing Authorization check in SAP PDCE | Product - SAP PDCE, Version – S4CORE 102, 103, S4COREOP 104, 105, 106, 107, 108",
      "source_url": "https://me.sap.com/notes/3483344",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "revised",
      "product": "SAP PDCE, Version – S4CORE 102, 103, S4COREOP 104, 105, 106, 107, 108",
      "platform": "SAP",
      "release_version": "S4CORE 102, 103, S4COREOP 104, 105, 106, 107, 108",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "High; CVSS 7.7",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 7.7,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2024-39592",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP PDCE, Version – S4CORE 102, 103, S4COREOP 104, 105, 106, 107, 108 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3483344 in its 2025-03 Security Patch Day release for SAP PDCE, Version – S4CORE 102, 103, S4COREOP 104, 105, 106, 107, 108. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2024-39592"
        ],
        "details": [
          {
            "id": "CVE-2024-39592",
            "title": "[CVE-2024-39592] Missing Authorization check in SAP PDCE",
            "summary": "Elements of PDCE does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This allows an attacker to read sensitive information causing high impact on the confidentiality of the application.",
            "score": 7.7,
            "version": "3.1",
            "severity": "High",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0042,
            "epssPercentile": 0.35173,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Within 7 days",
            "urgencyReason": "High technical severity; prioritise exposed affected systems while verifying vendor guidance.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-03-3549494",
      "slug": "sap-2025-03-3549494",
      "cycle_id": "2025-03",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3549494",
      "title": "Assess and apply SAP security advisory 3549494",
      "source_title": "[CVE-2025-23185] Information Disclosure in SAP Business Objects Business Intelligence Platform | Product - SAP Business Objects Business Intelligence Platform, Version - ENTERPRISE 430, 2025, 2027",
      "source_url": "https://me.sap.com/notes/3549494",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "SAP Business Objects Business Intelligence Platform, Version - ENTERPRISE 430, 2025, 2027",
      "platform": "SAP",
      "release_version": "ENTERPRISE 430, 2025, 2027",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 4.1",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 4.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-23185",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP Business Objects Business Intelligence Platform, Version - ENTERPRISE 430, 2025, 2027 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3549494 in its 2025-03 Security Patch Day release for SAP Business Objects Business Intelligence Platform, Version - ENTERPRISE 430, 2025, 2027. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-23185"
        ],
        "details": [
          {
            "id": "CVE-2025-23185",
            "title": "Information Disclosure in SAP Business Objects Business Intelligence Platform",
            "summary": "Due to improper error handling in SAP Business Objects Business Intelligence Platform, technical details of the application are revealed in exceptions thrown to the user and in stack traces. Only an attacker with administrator level privileges has access to this disclosed information, and they could use it to craft further exploits. There is no impact on the integrity and availability of the application.",
            "score": 4.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0028,
            "epssPercentile": 0.20242,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "HIGH",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-03-3552144",
      "slug": "sap-2025-03-3552144",
      "cycle_id": "2025-03",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3552144",
      "title": "Assess and apply SAP security advisory 3552144",
      "source_title": "[CVE-2025-25244] Missing Authorization Check in SAP Business Warehouse (Process Chains) Product – SAP Business Warehouse (Process Chains), Version – DW4CORE 100, DW4CORE 200, DW4CORE 300, DW4CORE 400, DW4CORE 914, SAP_BW 730, SAP_BW 731, SAP_BW 740, SAP_BW 750",
      "source_url": "https://me.sap.com/notes/3552144",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "SAP Business Warehouse (Process Chains), Version – DW4CORE 100, DW4CORE 200, DW4CORE 300, DW4CORE 400, DW4CORE 914, SAP_BW 730, SAP_BW 731, SAP_BW 740, SAP_BW 750",
      "platform": "SAP",
      "release_version": "DW4CORE 100, DW4CORE 200, DW4CORE 300, DW4CORE 400, DW4CORE 914, SAP_BW 730, SAP_BW 731, SAP_BW 740, SAP_BW 750",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 5.7",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 5.7,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-25244",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP Business Warehouse (Process Chains), Version – DW4CORE 100, DW4CORE 200, DW4CORE 300, DW4CORE 400, DW4CORE 914, SAP_BW 730, SAP_BW 731, SAP_BW 740, SAP_BW 750 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3552144 in its 2025-03 Security Patch Day release for SAP Business Warehouse (Process Chains), Version – DW4CORE 100, DW4CORE 200, DW4CORE 300, DW4CORE 400, DW4CORE 914, SAP_BW 730, SAP_BW 731, SAP_BW 740, SAP_BW 750. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-25244"
        ],
        "details": [
          {
            "id": "CVE-2025-25244",
            "title": "Missing Authorization Check in SAP Business Warehouse (Process Chains)",
            "summary": "SAP Business Warehouse (Process Chains) allows an attacker to manipulate the process execution due to missing authorization check. An attacker with display authorization for the process chain object could set one or all processes to be skipped. This means corresponding activities, such as data loading, activation, or deletion, will not be executed as initially modeled. This could lead to unexpected results in busines",
            "score": 5.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00209,
            "epssPercentile": 0.11103,
            "epssDate": "2026-09-06",
            "attackVector": "ADJACENT",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-03-3552824",
      "slug": "sap-2025-03-3552824",
      "cycle_id": "2025-03",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3552824",
      "title": "Assess and apply SAP security advisory 3552824",
      "source_title": "[CVE-2025-26659] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (applications based on SAP GUI for HTML) Product- SAP NetWeaver Application Server ABAP (applications based on SAP GUI for HTML), Versions – KRNL64UC 7.53, KERNEL 7.54, KERNEL 7.77, KERNEL 7.89, KERNEL 7.93, KERNEL 9.14",
      "source_url": "https://me.sap.com/notes/3552824",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "SAP NetWeaver Application Server ABAP (applications based on SAP GUI for HTML), Versions – KRNL64UC 7.53, KERNEL 7.54, KERNEL 7.77, KERNEL 7.89, KERNEL 7.93, KERNEL 9.14",
      "platform": "SAP",
      "release_version": "s – KRNL64UC 7.53, KERNEL 7.54, KERNEL 7.77, KERNEL 7.89, KERNEL 7.93, KERNEL 9.14",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 6.1",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 6.1,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-26659",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP NetWeaver Application Server ABAP (applications based on SAP GUI for HTML), Versions – KRNL64UC 7.53, KERNEL 7.54, KERNEL 7.77, KERNEL 7.89, KERNEL 7.93, KERNEL 9.14 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3552824 in its 2025-03 Security Patch Day release for SAP NetWeaver Application Server ABAP (applications based on SAP GUI for HTML), Versions – KRNL64UC 7.53, KERNEL 7.54, KERNEL 7.77, KERNEL 7.89, KERNEL 7.93, KERNEL 9.14. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-26659"
        ],
        "details": [
          {
            "id": "CVE-2025-26659",
            "title": "Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (applications based on SAP GUI for HTML)",
            "summary": "SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to DOM-basedCross-Site Scripting (XSS) vulnerability. This allows an attacker with no privileges, to craft a malicious web message that exploits WEBGUI functionality. On successful exploitation, the malicious JavaScript payload executes in the scope of victim�s browser potentially compromising their data and/or manipula",
            "score": 6.1,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.0023,
            "epssPercentile": 0.13785,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-03-3557131",
      "slug": "sap-2025-03-3557131",
      "cycle_id": "2025-03",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3557131",
      "title": "Assess and apply SAP security advisory 3557131",
      "source_title": "[CVE-2025-23188] Missing Authorization check in SAP S/4HANA (RBD) | Product- SAP S/4HANA (RBD), Versions – S4CORE 102, 103, 104, 105, 106, 107, 108, EA-FINSERV 618, EA-FINSERV 800",
      "source_url": "https://me.sap.com/notes/3557131",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "SAP S/4HANA (RBD), Versions – S4CORE 102, 103, 104, 105, 106, 107, 108, EA-FINSERV 618, EA-FINSERV 800",
      "platform": "SAP",
      "release_version": "s – S4CORE 102, 103, 104, 105, 106, 107, 108, EA-FINSERV 618, EA-FINSERV 800",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 4.3",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 4.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-23188",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP S/4HANA (RBD), Versions – S4CORE 102, 103, 104, 105, 106, 107, 108, EA-FINSERV 618, EA-FINSERV 800 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3557131 in its 2025-03 Security Patch Day release for SAP S/4HANA (RBD), Versions – S4CORE 102, 103, 104, 105, 106, 107, 108, EA-FINSERV 618, EA-FINSERV 800. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-23188"
        ],
        "details": [
          {
            "id": "CVE-2025-23188",
            "title": "Missing Authorization check in SAP S/4HANA (RBD)",
            "summary": "An authenticated user with low privileges can exploit a missing authorization check in an IBS module of FS-RBD, allowing unauthorized access to perform actions beyond their intended permissions. This causes a low impact on integrity with no impact on confidentiality and availability.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00235,
            "epssPercentile": 0.14366,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-03-3557459",
      "slug": "sap-2025-03-3557459",
      "cycle_id": "2025-03",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3557459",
      "title": "Assess and apply SAP security advisory 3557459",
      "source_title": "[CVE-2025-0062] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence) Product- SAP BusinessObjects Business Intelligence Platform, Version – ENTERPRISE 430, 2025, ENTERPRISECLIENTTOOLS 430, 2025",
      "source_url": "https://me.sap.com/notes/3557459",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "SAP BusinessObjects Business Intelligence Platform, Version – ENTERPRISE 430, 2025, ENTERPRISECLIENTTOOLS 430, 2025",
      "platform": "SAP",
      "release_version": "ENTERPRISE 430, 2025, ENTERPRISECLIENTTOOLS 430, 2025",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 4.7",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 4.7,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-0062",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP BusinessObjects Business Intelligence Platform, Version – ENTERPRISE 430, 2025, ENTERPRISECLIENTTOOLS 430, 2025 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3557459 in its 2025-03 Security Patch Day release for SAP BusinessObjects Business Intelligence Platform, Version – ENTERPRISE 430, 2025, ENTERPRISECLIENTTOOLS 430, 2025. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-0062"
        ],
        "details": [
          {
            "id": "CVE-2025-0062",
            "title": "Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence)",
            "summary": "SAP BusinessObjects Business Intelligence Platform allows an attacker to inject JavaScript code in Web Intelligence reports. This code is then executed in the victim's browser each time the vulnerable page is visited by the victim. On successful exploitation, an attacker could cause limited impact on confidentiality and integrity within the scope of victim�s browser. There is no impact on availability. This vulnerabi",
            "score": 4.7,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00273,
            "epssPercentile": 0.19407,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "HIGH",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-03-3557469",
      "slug": "sap-2025-03-3557469",
      "cycle_id": "2025-03",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3557469",
      "title": "Assess and apply SAP security advisory 3557469",
      "source_title": "[CVE-2025-25245] Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence) Product- SAP BusinessObjects Business Intelligence Platform (Web Intelligence), Version – ENTERPRISE 430, 2025",
      "source_url": "https://me.sap.com/notes/3557469",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "SAP BusinessObjects Business Intelligence Platform (Web Intelligence), Version – ENTERPRISE 430, 2025",
      "platform": "SAP",
      "release_version": "ENTERPRISE 430, 2025",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 5.4",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 5.4,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-25245",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP BusinessObjects Business Intelligence Platform (Web Intelligence), Version – ENTERPRISE 430, 2025 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3557469 in its 2025-03 Security Patch Day release for SAP BusinessObjects Business Intelligence Platform (Web Intelligence), Version – ENTERPRISE 430, 2025. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-25245"
        ],
        "details": [
          {
            "id": "CVE-2025-25245",
            "title": "Cross-Site Scripting (XSS) vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Intelligence)",
            "summary": "SAP BusinessObjects Business Intelligence Platform (Web Intelligence) contains a deprecated web application endpoint that is not properly secured. An attacker could take advantage of this by injecting a malicious url in the data returned to the user. On successful exploitation, there could be a limited impact on confidentiality and integrity within the scope of victim�s browser. There is no impact on availability.",
            "score": 5.4,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00227,
            "epssPercentile": 0.13286,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "patchState": "Patch available",
            "fixed": "An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    },
    {
      "id": "sap-2025-03-3557655",
      "slug": "sap-2025-03-3557655",
      "cycle_id": "2025-03",
      "vendor_id": "sap",
      "vendor_name": "SAP",
      "source_id": "sap-security-patch-day",
      "advisory_id": "3557655",
      "title": "Assess and apply SAP security advisory 3557655",
      "source_title": "[CVE-2025-26660] Broken Access Control in SAP Fiori apps (Posting Library) Product- SAP Fiori apps (Posting Library), Version – S4CORE 103, 104, 105, 106, 107, 108",
      "source_url": "https://me.sap.com/notes/3557655",
      "published_at": "2025-03-11",
      "updated_at": "2025-03-11",
      "status": "active",
      "product": "SAP Fiori apps (Posting Library), Version – S4CORE 103, 104, 105, 106, 107, 108",
      "platform": "SAP",
      "release_version": "S4CORE 103, 104, 105, 106, 107, 108",
      "action_type": "deploy-patch",
      "restart_required": "unknown",
      "vendor_severity": "Medium; CVSS 4.3",
      "evidence": {
        "kev": "unknown",
        "confirmed_exploitation": "not-stated",
        "vendor_exploitability": null,
        "max_cvss": 4.3,
        "max_cvss_version": "3.1",
        "max_cvss_cve": "CVE-2025-26660",
        "max_epss": null,
        "epss_checked_at": null
      },
      "deployment": {
        "prerequisites": [
          "Confirm the affected product, edition, architecture and current build before deployment."
        ],
        "sequencing": [
          "Review the entitled SAP Note and apply prerequisites in the vendor-stated order."
        ],
        "downtime": "Downtime and restart impact are not fully stated in the reviewed public source.",
        "rollback": [
          "Capture the current version and a recoverable backup or snapshot before the change.",
          "Use the vendor-supported uninstall or recovery path when one is available."
        ],
        "workarounds": [
          "No vendor workaround is asserted unless it appears in the official advisory."
        ],
        "guidance_basis": "mixed"
      },
      "environment_questions": [
        "Is SAP Fiori apps (Posting Library), Version – S4CORE 103, 104, 105, 106, 107, 108 exposed to untrusted networks or content?",
        "Does this update affect an identity, management, backup or other control-plane system?",
        "Are compensating controls tested and monitored until the selected patch window?"
      ],
      "urgency": {
        "tier": "next-maintenance-window",
        "confidence": "medium",
        "reason_codes": [
          "FIX_AVAILABLE",
          "ROUTINE_REVIEW"
        ]
      },
      "summary": "SAP lists 3557655 in its 2025-03 Security Patch Day release for SAP Fiori apps (Posting Library), Version – S4CORE 103, 104, 105, 106, 107, 108. The public bulletin links 1 CVE; entitled SAP Note content remains the deployment authority.",
      "cves": {
        "state": "complete-for-public-bulletin",
        "vendor_stated_count": 1,
        "ids": [
          "CVE-2025-26660"
        ],
        "details": [
          {
            "id": "CVE-2025-26660",
            "title": "Broken Access Control in SAP Fiori apps (Posting Library)",
            "summary": "SAP Fiori applications using the posting library fail to properly configure security settings during the setup process, leaving them at default or inadequately defined. This vulnerability allows an attacker with low privileges to bypass access controls within the application, enabling them to potentially modify data. Confidentiality and Availability are not impacted.",
            "score": 4.3,
            "version": "3.1",
            "severity": "Medium",
            "cvssSource": "CNA",
            "wild": false,
            "wildDetail": "No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.",
            "publicExploit": "No public exploit",
            "publicExploitDetail": "No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.",
            "epss": 0.00289,
            "epssPercentile": 0.21175,
            "epssDate": "2026-09-06",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "patchState": "Awaiting fix",
            "fixed": "No fixed version is explicitly recorded in the structured CVE data.",
            "urgency": "Scheduled",
            "urgencyReason": "Medium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.",
            "confidence": "High"
          }
        ]
      },
      "known_issues": [],
      "deployment_effects": [
        "Confirm the installed SAP component and version before applying the correction.",
        "Use entitled SAP Note content for prerequisites, correction instructions and rollback planning."
      ],
      "data_gaps": [
        "Authenticated SAP correction content is not copied into the public catalogue.",
        "Restart and downtime requirements require review of the entitled SAP Note."
      ],
      "provenance": [
        {
          "field": "note_identity_product_and_versions",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        },
        {
          "field": "cve_relationships_and_vendor_signal",
          "source_path": "sap-patch-day/table",
          "verification_state": "verified-automatic",
          "retrieved_at": "2026-08-26T11:55:31Z"
        }
      ],
      "revisions": [
        {
          "revision": 1,
          "observed_at": "2025-03-11",
          "summary": "Captured from the scheduled SAP Security Patch Day bulletin."
        }
      ],
      "review": {
        "state": "approved-publication",
        "reviewed_at": "2026-08-26T11:57:02Z",
        "publication_approved": true,
        "rationale": "The note identity, Patch Day inclusion, product, public version expression, vendor priority, CVSS and public CVE relationships were generated from the official SAP Patch Day table and passed structural validation. The project owner requested publication of every Patch Tuesday cycle from January 2025 onward. All 20 cycles passed the official Microsoft, Adobe and SAP source completeness gates, structural validation and bounded historical review."
      }
    }
  ]
}